Vulnerability Description
SAP BTP Security Services Integration Library ([Java] cloud-security-services-integration-library) - versions below 2.17.0 and versions from 3.0.0 to before 3.3.0, allow under certain conditions an escalation of privileges. On successful exploitation, an unauthenticated attacker can obtain arbitrary permissions within the application.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sap | Cloud-Security-Services-Integration-Library | < 2.17.0 |
Related Weaknesses (CWE)
References
- https://blogs.sap.com/2023/12/12/unveiling-critical-security-updates-sap-btp-secVendor Advisory
- https://github.com/SAP/cloud-security-services-integration-library/Product
- https://github.com/SAP/cloud-security-services-integration-library/security/adviVendor Advisory
- https://me.sap.com/notes/3411067Permissions Required
- https://me.sap.com/notes/3413475
- https://mvnrepository.com/artifact/com.sap.cloud.security.xsuaa/spring-xsuaaProduct
- https://mvnrepository.com/artifact/com.sap.cloud.security/java-securityProduct
- https://mvnrepository.com/artifact/com.sap.cloud.security/spring-securityProduct
- https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.htmlVendor Advisory
- https://blogs.sap.com/2023/12/12/unveiling-critical-security-updates-sap-btp-secVendor Advisory
- https://github.com/SAP/cloud-security-services-integration-library/Product
- https://github.com/SAP/cloud-security-services-integration-library/security/adviVendor Advisory
- https://me.sap.com/notes/3411067Permissions Required
- https://me.sap.com/notes/3413475
- https://mvnrepository.com/artifact/com.sap.cloud.security.xsuaa/spring-xsuaaProduct
FAQ
What is CVE-2023-50422?
CVE-2023-50422 is a vulnerability with a CVSS score of 9.1 (CRITICAL). SAP BTP Security Services Integration Library ([Java] cloud-security-services-integration-library) - versions below 2.17.0 and versions from 3.0.0 to before 3.3.0, allow under certain conditions an es...
How severe is CVE-2023-50422?
CVE-2023-50422 has been rated CRITICAL with a CVSS base score of 9.1/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2023-50422?
Check the references section above for vendor advisories and patch information. Affected products include: Sap Cloud-Security-Services-Integration-Library.