CVE-2023-37487 Vulnerability Details

  /     /     /  

CVE-2023-37487 Metadata Quick Info

CVE Published: 08/08/2023 | CVE Updated: 10/10/2024 | CVE Year: 2023
Source: sap | Vendor: SAP_SE | Product: SAP Business One (Service Layer)
Status : PUBLISHED

CVE-2023-37487 Description

SAP Business One (Service Layer) - version 10.0, allows an authenticated attacker with deep knowledge perform certain operation to access unintended data over the network which could lead to high impact on confidentiality with no impact on integrity and availability of the application

Metrics

CVSS Version: 3.1 | Base Score: 5.3 MEDIUM
Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N

l➤ Exploitability Metrics:
    Attack Vector (AV)* NETWORK
    Attack Complexity (AC)* HIGH
    Privileges Required (PR)* LOW
    User Interaction (UI)* NONE
    Scope (S)* UNCHANGED

l➤ Impact Metrics:
    Confidentiality Impact (C)* HIGH
    Integrity Impact (I)* NONE
    Availability Impact (A)* NONE

Weakness Enumeration (CWE)

CWE-ID: CWE-497
CWE Name: CWE-497: Exposure of Sensitive System Information to an Unauthorized Control Sphere
Source: SAP_SE

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).