An unauthenticated attacker in SAP Web Dispatcher - versions WEBDISP 7.49, WEBDISP 7.53, WEBDISP 7.54, WEBDISP 7.77, WEBDISP 7.81, WEBDISP 7.85, WEBDISP 7.88, WEBDISP 7.89, WEBDISP 7.90, KERNEL 7.49, KERNEL 7.53, KERNEL 7.54 KERNEL 7.77, KERNEL 7.81, KERNEL 7.85, KERNEL 7.88, KERNEL 7.89, KERNEL 7.90, KRNL64NUC 7.49, KRNL64UC 7.49, KRNL64UC 7.53, HDB 2.00, XS_ADVANCED_RUNTIME 1.00, SAP_EXTENDED_APP_SERVICES 1, can submit a malicious crafted request over a network to a front-end server which may, over several attempts, result in a back-end server confusing the boundaries of malicious and legitimate messages. This can result in the back-end server executing a malicious payload which can be used to read or modify information on the server or make it temporarily unavailable.
References
Link | Resource |
---|---|
https://me.sap.com/notes/3233899 | Permissions Required |
https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html | Vendor Advisory |
https://me.sap.com/notes/3233899 | Permissions Required |
https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 08:06
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.6 |
References | () https://me.sap.com/notes/3233899 - Permissions Required | |
References | () https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html - Vendor Advisory |
18 Jul 2023, 18:31
Type | Values Removed | Values Added |
---|---|---|
References | (MISC) https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html - Vendor Advisory | |
References | (MISC) https://me.sap.com/notes/3233899 - Permissions Required | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.4 |
CPE | cpe:2.3:a:sap:web_dispatcher:7.81:*:*:*:*:*:*:* cpe:2.3:a:sap:web_dispatcher:kernel_7.53:*:*:*:*:*:*:* cpe:2.3:a:sap:web_dispatcher:7.85:*:*:*:*:*:*:* cpe:2.3:a:sap:web_dispatcher:krnl64uc_7.53:*:*:*:*:*:*:* cpe:2.3:a:sap:web_dispatcher:hdb_2.00:*:*:*:*:*:*:* cpe:2.3:a:sap:web_dispatcher:7.88:*:*:*:*:*:*:* cpe:2.3:a:sap:web_dispatcher:kernel_7.49:*:*:*:*:*:*:* cpe:2.3:a:sap:web_dispatcher:sap_extended_app_services_1:*:*:*:*:*:*:* cpe:2.3:a:sap:web_dispatcher:7.54:*:*:*:*:*:*:* cpe:2.3:a:sap:web_dispatcher:xs_advanced_runtime_1.00:*:*:*:*:*:*:* cpe:2.3:a:sap:web_dispatcher:kernel_7.54:*:*:*:*:*:*:* cpe:2.3:a:sap:web_dispatcher:krnl64nuc_7.49:*:*:*:*:*:*:* cpe:2.3:a:sap:web_dispatcher:7.77:*:*:*:*:*:*:* cpe:2.3:a:sap:web_dispatcher:7.53:*:*:*:*:*:*:* cpe:2.3:a:sap:web_dispatcher:7.90:*:*:*:*:*:*:* cpe:2.3:a:sap:web_dispatcher:krnl64uc_7.49:*:*:*:*:*:*:* cpe:2.3:a:sap:web_dispatcher:kernel_7.85:*:*:*:*:*:*:* cpe:2.3:a:sap:web_dispatcher:7.89:*:*:*:*:*:*:* cpe:2.3:a:sap:web_dispatcher:kernel_7.90:*:*:*:*:*:*:* cpe:2.3:a:sap:web_dispatcher:kernel_7.81:*:*:*:*:*:*:* cpe:2.3:a:sap:web_dispatcher:7.49:*:*:*:*:*:*:* cpe:2.3:a:sap:web_dispatcher:kernel_7.89:*:*:*:*:*:*:* cpe:2.3:a:sap:web_dispatcher:kernel_7.77:*:*:*:*:*:*:* cpe:2.3:a:sap:web_dispatcher:kernel_7.88:*:*:*:*:*:*:* |
|
First Time |
Sap web Dispatcher
Sap |
11 Jul 2023, 03:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-07-11 03:15
Updated : 2024-11-21 08:06
NVD link : CVE-2023-33987
Mitre link : CVE-2023-33987
CVE.ORG link : CVE-2023-33987
JSON object : View
Products Affected
sap
- web_dispatcher
CWE
CWE-444
Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')