137 lines
4.4 KiB
JSON
Raw Normal View History

{
"id": "CVE-2023-39436",
"sourceIdentifier": "cna@sap.com",
"published": "2023-08-08T01:15:19.150",
"lastModified": "2023-08-09T18:19:29.723",
"vulnStatus": "Analyzed",
"descriptions": [
{
"lang": "en",
"value": "SAP Supplier Relationship Management -versions 600, 602, 603, 604, 605, 606, 616, 617, allows an unauthorized attacker to discover information relating to\u00a0SRM within Vendor Master Data for Business Partners replication functionality.This information could be used to allow the attacker to specialize their attacks against\u00a0SRM.\n\n"
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "CHANGED",
"confidentialityImpact": "LOW",
"integrityImpact": "NONE",
"availabilityImpact": "NONE",
"baseScore": 5.8,
"baseSeverity": "MEDIUM"
},
"exploitabilityScore": 3.9,
"impactScore": 1.4
},
{
"source": "cna@sap.com",
"type": "Secondary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "CHANGED",
"confidentialityImpact": "LOW",
"integrityImpact": "NONE",
"availabilityImpact": "NONE",
"baseScore": 5.8,
"baseSeverity": "MEDIUM"
},
"exploitabilityScore": 3.9,
"impactScore": 1.4
}
]
},
"weaknesses": [
{
"source": "cna@sap.com",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-200"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:sap:supplier_relationship_management:600:*:*:*:*:*:*:*",
"matchCriteriaId": "55527525-88C2-4FAD-AD3F-023928317556"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:sap:supplier_relationship_management:602:*:*:*:*:*:*:*",
"matchCriteriaId": "15FDAEAF-58BD-4839-839F-A1E8C8E0E0AE"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:sap:supplier_relationship_management:603:*:*:*:*:*:*:*",
"matchCriteriaId": "794DE5E4-B5A6-4ACC-8EBF-F76FCAD7369C"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:sap:supplier_relationship_management:604:*:*:*:*:*:*:*",
"matchCriteriaId": "685CA87A-7F6F-4D75-83D9-C5F26201257D"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:sap:supplier_relationship_management:605:*:*:*:*:*:*:*",
"matchCriteriaId": "189F4096-39A5-44E6-B954-70B45FA1F695"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:sap:supplier_relationship_management:606:*:*:*:*:*:*:*",
"matchCriteriaId": "24247E81-67E8-42DE-9871-2EC7F0960A98"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:sap:supplier_relationship_management:616:*:*:*:*:*:*:*",
"matchCriteriaId": "2EFCE15C-77A9-4C6E-8616-3F7EBA1EB220"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:sap:supplier_relationship_management:617:*:*:*:*:*:*:*",
"matchCriteriaId": "67BE6CAE-5A02-4567-ADEA-2B16C763CA06"
}
]
}
]
}
],
"references": [
{
"url": "https://me.sap.com/notes/2067220",
"source": "cna@sap.com",
"tags": [
"Permissions Required"
]
},
{
"url": "https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html",
"source": "cna@sap.com",
"tags": [
"Vendor Advisory"
]
}
]
}