← volver
CVE-2023-39436mediumCWE-306

Information Disclosure in SAP Supplier Relationship Management

13Vexday Risk Score

Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.

ssvc Trackcvss 5.8epss 0.4%
probabilidad de explotación
0.4%top 62% de las CVE
explotación observada
noninguna fuente lo reporta
SAP Supplier Relationship Management -versions 600, 602, 603, 604, 605, 606, 616, 617, allows an unauthorized attacker to discover information relating to SRM within Vendor Master Data for Business Partners replication functionality.This information could be used to allow the attacker to specialize their attacks against SRM.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N