In SAP CRM - versions 700, 701, 702, 712, 713, an attacker who is authenticated with a non-administrative role and a common remote execution authorization can use a vulnerable interface to execute an application function to perform actions which they would not normally be permitted to perform. Depending on the function executed, the attack can can have limited impact on confidentiality and integrity of non-critical user or application data and application availability.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: sap

Published: 2023-04-11T02:50:00.642Z

Updated: 2023-04-11T20:19:16.988Z

Reserved: 2023-03-07T07:53:14.887Z


Link: CVE-2023-27897

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2023-04-11T03:15:07.613

Modified: 2023-04-14T19:47:31.197


Link: CVE-2023-27897

JSON object: View

cve-icon Redhat Information

No data.

CWE