CVE-2023-33987
11.07.2023, 03:15
An unauthenticated attacker in SAP Web Dispatcher - versions WEBDISP 7.49, WEBDISP 7.53, WEBDISP 7.54, WEBDISP 7.77, WEBDISP 7.81, WEBDISP 7.85, WEBDISP 7.88, WEBDISP 7.89, WEBDISP 7.90, KERNEL 7.49, KERNEL 7.53, KERNEL 7.54 KERNEL 7.77, KERNEL 7.81, KERNEL 7.85, KERNEL 7.88, KERNEL 7.89, KERNEL 7.90, KRNL64NUC 7.49, KRNL64UC 7.49, KRNL64UC 7.53, HDB 2.00, XS_ADVANCED_RUNTIME 1.00, SAP_EXTENDED_APP_SERVICES 1, can submit a malicious crafted request over a network to a front-end server whichmay, over several attempts, result in a back-end server confusing the boundaries of malicious and legitimatemessages. This can result in the back-end server executing a malicious payload which can be used to read ormodify information on the server or make it temporarily unavailable.
Vendor | Product | Version |
---|---|---|
sap | web_dispatcher | 7.49 |
sap | web_dispatcher | 7.53 |
sap | web_dispatcher | 7.54 |
sap | web_dispatcher | 7.77 |
sap | web_dispatcher | 7.81 |
sap | web_dispatcher | 7.85 |
sap | web_dispatcher | 7.88 |
sap | web_dispatcher | 7.89 |
sap | web_dispatcher | 7.90 |
𝑥
= Vulnerable software versions