CVE-2023-0017 CRITICAL

CVE-2023-0017: Improper access control in SAP NetWeaver AS for Java

Vendor Sap
Product NetWeaver AS for Java
Weakness CWE-284
Published January 10, 2023
Last update April 9, 2025

CVSS base score

9.4/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L

What the vulnerability does

Description

An unauthenticated attacker in SAP NetWeaver AS for Java - version 7.50, due to improper access control, can attach to an open interface and make use of an open naming and directory API to access services which can be used to perform unauthorized operations affecting users and data on the current system. This could allow the attacker to have full read access to user data, make modifications to user data, and make services within the system unavailable.

Key dates

Disclosure timeline

January 10, 2023 CVE published
April 9, 2025 Record updated