CVE-2023-50422

SAP BTP Security Services Integration Library ([Java] cloud-security-services-integration-library) - versions below 2.17.0 and versions from 3.0.0 to before 3.3.0, allow under certain conditions an escalation of privileges. On successful exploitation, an unauthenticated attacker can obtain arbitrary permissions within the application.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:sap:cloud-security-services-integration-library:*:*:*:*:*:java:*:*
cpe:2.3:a:sap:cloud-security-services-integration-library:*:*:*:*:*:java:*:*

History

28 Sep 2024, 23:15

Type Values Removed Values Added
CWE CWE-269 CWE-749
Summary (en) SAP BTP Security Services Integration Library ([Java] cloud-security-services-integration-library) - versions below 2.17.0 and versions from 3.0.0 to before 3.3.0, allow under certain conditions an escalation of privileges. On successful exploitation, an unauthenticated attacker can obtain arbitrary permissions within the application. (en) SAP BTP Security Services Integration Library ([Java] cloud-security-services-integration-library) - versions below 2.17.0 and versions from 3.0.0 to before 3.3.0, allow under certain conditions an escalation of privileges. On successful exploitation, an unauthenticated attacker can obtain arbitrary permissions within the application.

09 Jan 2024, 02:15

Type Values Removed Values Added
References
  • () https://me.sap.com/notes/3413475 -

15 Dec 2023, 16:53

Type Values Removed Values Added
New CVE

Information

Published : 2023-12-12 02:15

Updated : 2024-09-28 23:15


NVD link : CVE-2023-50422

Mitre link : CVE-2023-50422

CVE.ORG link : CVE-2023-50422


JSON object : View

Products Affected

sap

  • cloud-security-services-integration-library
CWE
CWE-749

Exposed Dangerous Method or Function