peter bassill · operator
$ cve CVE-2023-0017 JSON

CVE-2023-0017

9.4
CRITICAL · CVSS 3.1 · EPSS 15.7% (pctl 97)

Patch early

EPSS 15.7% — above the 10% action threshold.

Description

An unauthenticated attacker in SAP NetWeaver AS for Java - version 7.50, due to improper access control, can attach to an open interface and make use of an open naming and directory API to access services which can be used to perform unauthorized operations affecting users and data on the current system. This could allow the attacker to have full read access to user data, make modifications to user data, and make services within the system unavailable.

Scoring

CVSS9.4 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
EPSS15.73% — more likely to be exploited than 97% of all CVEs
WeaknessCWE-284
On CISA KEVno
Public exploitnone known
Published2023-01-10
Last modified2026-06-17

Affected (1)

VendorProduct
sapnetweaver application server for java

References

→ the Explorer  ·  watch your stack  ·  NVD