« Volver al listado

CVE-2023-32114

Estado: ModificadaBaja (2.7)—

SAP NetWeaver (Change and Transport System) - versions 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, allows an authenticated user with admin privileges to maliciously run a benchmark program repeatedly in intent to slowdown or make the server unavailable which may lead to a limited impact on Availability with No impact on Confidentiality and Integrity of the application.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-32114",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2023-32114",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-01-03T02:06:20.309745Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "cna@sap.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 2.7,
          "attackVector": "NETWORK",
          "baseSeverity": "LOW",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "LOW",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 1.2
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 2.7,
          "attackVector": "NETWORK",
          "baseSeverity": "LOW",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "LOW",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 1.2
      }
    ]
  },
  "affected": [
    {
      "source": "cna@sap.com",
      "affectedData": [
        {
          "vendor": "SAP_SE",
          "product": "SAP NetWeaver (Change and Transport System)",
          "versions": [
            {
              "status": "affected",
              "version": "702"
            },
            {
              "status": "affected",
              "version": "731"
            },
            {
              "status": "affected",
              "version": "740"
            },
            {
              "status": "affected",
              "version": "750"
            },
            {
              "status": "affected",
              "version": "751"
            },
            {
              "status": "affected",
              "version": "752"
            },
            {
              "status": "affected",
              "version": "753"
            },
            {
              "status": "affected",
              "version": "754"
            },
            {
              "status": "affected",
              "version": "755"
            },
            {
              "status": "affected",
              "version": "756"
            },
            {
              "status": "affected",
              "version": "757"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2023-06-13T03:15:09.393",
  "references": [
    {
      "url": "https://launchpad.support.sap.com/#/notes/3325642",
      "tags": [
        "Permissions Required"
      ],
      "source": "cna@sap.com"
    },
    {
      "url": "https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cna@sap.com"
    },
    {
      "url": "https://launchpad.support.sap.com/#/notes/3325642",
      "tags": [
        "Permissions Required"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "cna@sap.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-732"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "SAP NetWeaver (Change and Transport System) - versions 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, allows an authenticated user with admin privileges to maliciously run a benchmark program repeatedly in intent to slowdown or make the server unavailable which may lead to a limited impact on Availability with No impact on Confidentiality and Integrity of the application."
    }
  ],
  "lastModified": "2026-06-17T05:58:06.730",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:sap:netweaver:702:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6A503ABF-8655-40D7-96AD-2D7F19A673AE"
            },
            {
              "criteria": "cpe:2.3:a:sap:netweaver:731:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8A9D5C5A-6963-438B-B0EA-2A621A34D8A9"
            },
            {
              "criteria": "cpe:2.3:a:sap:netweaver:740:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BFFA1591-0304-4FAE-A6A7-72D04D1F41A3"
            },
            {
              "criteria": "cpe:2.3:a:sap:netweaver:750:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7940A9AF-308E-4CE5-BA19-7A3DCF49F644"
            },
            {
              "criteria": "cpe:2.3:a:sap:netweaver:751:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C09428E4-45BB-414D-9F3D-AA5C73D2DD5E"
            },
            {
              "criteria": "cpe:2.3:a:sap:netweaver:752:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5ED0BA7D-939D-4B05-81A3-9F991C8C04F9"
            },
            {
              "criteria": "cpe:2.3:a:sap:netweaver:753:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0C2BF545-A7DC-4BB6-B894-D04CF163DD88"
            },
            {
              "criteria": "cpe:2.3:a:sap:netweaver:754:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A75B2F18-60BE-41B5-82CB-520F794F2004"
            },
            {
              "criteria": "cpe:2.3:a:sap:netweaver:755:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E31620E5-30FC-4545-A430-AAA77A66B51A"
            },
            {
              "criteria": "cpe:2.3:a:sap:netweaver:756:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9724E131-9893-4630-96A2-EB6032D98C58"
            },
            {
              "criteria": "cpe:2.3:a:sap:netweaver:757:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8FEBCDDF-4828-45D1-A81D-FFB50261DBCA"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cna@sap.com"
}