CVE-2023-0014
SAP NetWeaver ABAP Server and ABAP Platform - versions SAP_BASIS 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, KERNEL 7.22, 7.53, 7.77, 7.81, 7.85, 7.89, KRNL64UC 7.22, 7.22EXT, 7.53, KRNL64NUC 7.22, 7.22EXT, creates information about system identity in an ambiguous format. This could lead to capture-replay vulnerability and may be exploited by malicious users to obtain illegitimate access to the system.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
- EPSS probability
- 0.41%
- CWE
- CWE-294
- Published
- 2023-01-10
- Last modified
- 2026-03-13
Affected products
- SAP NetWeaver ABAP Server and ABAP Platform
- SAP NetWeaver ABAP Server and ABAP Platform
- SAP NetWeaver ABAP Server and ABAP Platform
- SAP NetWeaver ABAP Server and ABAP Platform
- SAP NetWeaver ABAP Server and ABAP Platform
- SAP NetWeaver ABAP Server and ABAP Platform
- SAP NetWeaver ABAP Server and ABAP Platform
- SAP NetWeaver ABAP Server and ABAP Platform
Weakness type
Related vulnerabilities
- CVE-2026-65905 — Apache Tomcat: Limited replay attack possible with DIGEST authentication
- CVE-2024-38438 — D-Link - CWE-294: Authentication Bypass by Capture-replay
- CVE-2025-6030 — Autoeastern Smart Keyless Entry System Replay Attack
- CVE-2025-6029 — KIA-branded Aftermarket Generic Smart Keyless Entry System Replay Attack
- CVE-2025-36593 — Dell OpenManage Network Integration, versions prior to 3.8, contains an Authentication Bypass by Capture-replay vulnerab
- CVE-2024-43099 — AutomationDirect DirectLogic H2-DM1E Authentication Bypass by Capture-replay
- CVE-2024-12839 — Changing Information Technology CGFIDO - Authentication Bypass
- CVE-2024-38284 — Authentication Bypass by Capture-replay in Motorola Solutions Vigilant Fixed LPR Coms Box (BCAV1F2-C600)