Vulnerability Database

289,784

Total vulnerabilities in the database

CVE-2023-33987

An unauthenticated attacker in SAP Web Dispatcher - versions WEBDISP 7.49, WEBDISP 7.53, WEBDISP 7.54, WEBDISP 7.77, WEBDISP 7.81, WEBDISP 7.85, WEBDISP 7.88, WEBDISP 7.89, WEBDISP 7.90, KERNEL 7.49, KERNEL 7.53, KERNEL 7.54 KERNEL 7.77, KERNEL 7.81, KERNEL 7.85, KERNEL 7.88, KERNEL 7.89, KERNEL 7.90, KRNL64NUC 7.49, KRNL64UC 7.49, KRNL64UC 7.53, HDB 2.00, XS_ADVANCED_RUNTIME 1.00, SAP_EXTENDED_APP_SERVICES 1, can submit a malicious crafted request over a network to a front-end server which may, over several attempts, result in a back-end server confusing the boundaries of malicious and legitimate messages. This can result in the back-end server executing a malicious payload which can be used to read or modify information on the server or make it temporarily unavailable.

  • Published: Jul 11, 2023
  • Updated: Jul 19, 2023
  • CVE: CVE-2023-33987
  • Severity: Critical
  • Exploit:

CVSS v3:

  • Severity: Critical
  • Score: 9.4
  • AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L

CWEs:

Software From Fixed in
sap / web_dispatcher 7.53 7.53.x
sap / web_dispatcher 7.77 7.77.x
sap / web_dispatcher 7.81 7.81.x
sap / web_dispatcher 7.49 7.49.x
sap / web_dispatcher 7.85 7.85.x
sap / web_dispatcher 7.89 7.89.x
sap / web_dispatcher krnl64uc_7.53 krnl64uc_7.53.x
sap / web_dispatcher krnl64nuc_7.49 krnl64nuc_7.49.x
sap / web_dispatcher kernel_7.49 kernel_7.49.x
sap / web_dispatcher kernel_7.53 kernel_7.53.x
sap / web_dispatcher kernel_7.54 kernel_7.54.x
sap / web_dispatcher kernel_7.77 kernel_7.77.x
sap / web_dispatcher kernel_7.81 kernel_7.81.x
sap / web_dispatcher kernel_7.85 kernel_7.85.x
sap / web_dispatcher kernel_7.89 kernel_7.89.x
sap / web_dispatcher kernel_7.88 kernel_7.88.x
sap / web_dispatcher kernel_7.90 kernel_7.90.x
sap / web_dispatcher 7.54 7.54.x
sap / web_dispatcher 7.88 7.88.x
sap / web_dispatcher 7.90 7.90.x
sap / web_dispatcher krnl64uc_7.49 krnl64uc_7.49.x
sap / web_dispatcher hdb_2.00 hdb_2.00.x
sap / web_dispatcher xs_advanced_runtime_1.00 xs_advanced_runtime_1.00.x
sap / web_dispatcher sap_extended_app_services_1 sap_extended_app_services_1.x