8.8
CVSSv3

CVE-2023-37491

Published: 08/08/2023 Updated: 09/08/2023
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

The ACL (Access Control List) of SAP Message Server - versions KERNEL 7.22, KERNEL 7.53, KERNEL 7.54, KERNEL 7.77, RNL64UC 7.22, RNL64UC 7.22EXT, RNL64UC 7.53, KRNL64NUC 7.22, KRNL64NUC 7.22EXT, can be bypassed in certain conditions, which may enable an authenticated malicious user to enter the network of the SAP systems served by the attacked SAP Message server. This may lead to unauthorized read and write of data as well as rendering the system unavailable.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

sap message server kernel_7.22

sap message server kernel_7.53

sap message server kernel_7.54

sap message server kernel_7.77

sap message server rnl64uc_7.22

sap message server rnl64uc_7.22ext

sap message server rnl64uc_7.53

sap message server krnl64nuc_7.22

sap message server krnl64nuc_7.22ex