
Cloud Vulnerability DB
A community-led vulnerabilities database
SAP NetWeaver Application Server ABAP and ABAP Platform versions (SAP_BASIS 700-804) contains a vulnerability where the system does not perform necessary authorization checks for authenticated users. The vulnerability was disclosed on August 7, 2023, and is tracked as CVE-2023-37492 (NVD).
The vulnerability is classified as a Missing Authorization (CWE-862) and Incorrect Authorization (CWE-863) issue. It has received a CVSS v3.1 base score of 6.5 (Medium) with vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N, indicating network accessibility, low attack complexity, and requiring low privileges with no user interaction (NVD).
The vulnerability allows an authenticated attacker to read sensitive information which could be used in subsequent serious attacks. The impact primarily affects confidentiality (rated as High), while integrity and availability remain unaffected (AttackerKB).
SAP has released security notes and patches to address this vulnerability. Organizations should refer to SAP Security Note 3348000 for detailed mitigation instructions (SAP Note).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."