Improper access control in SAP NetWeaver AS JAVA - CVE-2023-24527
Published: April 14, 2023
Vulnerability identifier: #VU75138
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-24527
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions within the Deploy Service API. A remote user can bypass implemented security restrictions and gain unauthorized access to the application.
Affected software
SAP NetWeaver AS JAVA
Watson CP4D Data Stores
Watson CP4D Data Stores
How to mitigate CVE-2023-24527
Install updates from vendor's website.
Watson CP4D Data Stores - update to 4.7.0