SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2023-0014

This could lead to capture-replay vulnerability and may be exploited by malicious users to obtain illegitimate access to the system.

CRITICAL 9.8EPSS 0.69%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (0.69%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

SAP NetWeaver ABAP Server and ABAP Platform - versions SAP_BASIS 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, KERNEL 7.22, 7.53, 7.77, 7.81, 7.85, 7.89, KRNL64UC 7.22, 7.22EXT, 7.53, KRNL64NUC 7.22, 7.22EXT, creates information about system identity in an ambiguous format. This could lead to capture-replay vulnerability and may be exploited by malicious users to obtain illegitimate access to the system.

CVSS 3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
0.69% probability · 51th percentile
CISA KEV
Not listed
Weakness
CWE-294
Affected
sap/netweaver application server abap · sap/netweaver application server abap kernel · sap/netweaver application server abap krnl64nuc · sap/netweaver application server abap krnl64uc
Source
cna@sap.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.