Improper access control in SAP GUI for Windows - CVE-2023-49580

 

Improper access control in SAP GUI for Windows - CVE-2023-49580

Published: December 19, 2023


Vulnerability identifier: #VU84580
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-49580
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.

The vulnerability exists due to improper access restrictions in SAP GUI for Windows and SAP GUI for Java. A remote attacker can bypass implemented security restrictions and gain access to sensitive information or create Layout configurations of the ABAP List Viewer.


Affected software

SAP GUI for Windows

How to mitigate CVE-2023-49580

Install updates from vendor's website.


External References

Related Security Bulletins