# CVE-2023-0014

## Summary

- **CVE ID:** CVE-2023-0014
- **Severity:** CRITICAL
- **CVSS Score:** 9 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H)
- **CWE:** CWE-294
- **Published:** Jan 10, 2023
- **Last Modified:** Mar 13, 2026

## Description

SAP NetWeaver ABAP Server and ABAP Platform - versions SAP_BASIS 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, KERNEL 7.22, 7.53, 7.77, 7.81, 7.85, 7.89, KRNL64UC 7.22, 7.22EXT, 7.53, KRNL64NUC 7.22, 7.22EXT, creates information about system identity in an ambiguous format. This could lead to capture-replay vulnerability and may be exploited by malicious users to obtain illegitimate access to the system.

## Affected Products

- SAP — NetWeaver ABAP Server and ABAP Platform (SAP_BASIS 701)
- SAP — NetWeaver ABAP Server and ABAP Platform (SAP_BASIS 702)
- SAP — NetWeaver ABAP Server and ABAP Platform (SAP_BASIS 710)
- SAP — NetWeaver ABAP Server and ABAP Platform (SAP_BASIS 711)
- SAP — NetWeaver ABAP Server and ABAP Platform (SAP_BASIS 730)
- SAP — NetWeaver ABAP Server and ABAP Platform (SAP_BASIS 731)
- SAP — NetWeaver ABAP Server and ABAP Platform (SAP_BASIS 740)
- SAP — NetWeaver ABAP Server and ABAP Platform (SAP_BASIS 750)
- SAP — NetWeaver ABAP Server and ABAP Platform (SAP_BASIS 751)
- SAP — NetWeaver ABAP Server and ABAP Platform (SAP_BASIS 752)
- SAP — NetWeaver ABAP Server and ABAP Platform (SAP_BASIS 753)
- SAP — NetWeaver ABAP Server and ABAP Platform (SAP_BASIS 754)
- SAP — NetWeaver ABAP Server and ABAP Platform (SAP_BASIS 755)
- SAP — NetWeaver ABAP Server and ABAP Platform (SAP_BASIS 756)
- SAP — NetWeaver ABAP Server and ABAP Platform (SAP_BASIS 757)
- SAP — NetWeaver ABAP Server and ABAP Platform (KERNEL 7.22)
- SAP — NetWeaver ABAP Server and ABAP Platform (KERNEL 7.53)
- SAP — NetWeaver ABAP Server and ABAP Platform (KERNEL 7.77)
- SAP — NetWeaver ABAP Server and ABAP Platform (KERNEL 7.81)
- SAP — NetWeaver ABAP Server and ABAP Platform (KERNEL 7.85)
- SAP — NetWeaver ABAP Server and ABAP Platform (KERNEL 7.89)
- SAP — NetWeaver ABAP Server and ABAP Platform (KRNL64UC 7.22)
- SAP — NetWeaver ABAP Server and ABAP Platform (KRNL64UC 7.22EXT)
- SAP — NetWeaver ABAP Server and ABAP Platform (KRNL64UC 7.53)
- SAP — NetWeaver ABAP Server and ABAP Platform (KRNL64NUC 7.22)
- SAP — NetWeaver ABAP Server and ABAP Platform (KRNL64NUC 7.22EXT)

## References

- [CNA](https://launchpad.support.sap.com/#/notes/3089413)
- [CNA](https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.41%
- **EPSS Percentile:** 61.0

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-17._