Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-27897


In SAP CRM - versions 700, 701, 702, 712, 713, an attacker who is authenticated with a non-administrative role and a common remote execution authorization can use a vulnerable interface to execute an application function to perform actions which they would not normally be permitted to perform. Depending on the function executed, the attack can can have limited impact on confidentiality and integrity of non-critical user or application data and application availability.


Published

2023-04-11T03:15:07.613

Last Modified

2024-11-21T07:53:39.440

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.0 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-94

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application sap customer_relationship_management 700 Yes
Application sap customer_relationship_management 701 Yes
Application sap customer_relationship_management 702 Yes
Application sap customer_relationship_management 712 Yes
Application sap customer_relationship_management 713 Yes

References