CVE Published: 13/06/2023 |
CVE Updated: 02/08/2024 |
CVE Year: 2023 Source: sap |
Vendor: SAP_SE |
Product: Master Data Synchronization (MDS COMPARE TOOL) Status : PUBLISHED
CVE-2023-32115 Description
An attacker can exploit MDS COMPARE TOOL and use specially crafted inputs to read and modify database commands, resulting in the retrieval of additional information persisted by the system.
Metrics
CVSS Version: 3.1 |
Base Score: 4.2 MEDIUM Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N
l➤ Exploitability Metrics: Attack Vector (AV)* LOCAL Attack Complexity (AC)* HIGH Privileges Required (PR)* LOW User Interaction (UI)* NONE Scope (S)* CHANGED