6.1
CVSSv3

CVE-2023-0021

Published: 14/03/2023 Updated: 07/11/2023
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

Due to insufficient encoding of user input, SAP NetWeaver - versions 700, 701, 702, 731, 740, 750, allows an unauthenticated malicious user to inject code that may expose sensitive data like user ID and password, which could lead to reflected Cross-Site scripting. These endpoints are normally exposed over the network and successful exploitation can partially impact confidentiality of the application.

Vulnerable Product Search on Vulmon Subscribe to Product

sap netweaver 701

sap netweaver 702

sap netweaver 700

sap netweaver 731

sap netweaver 740

sap netweaver 750