AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2023-23851

MEDIUM · CVSS 5.4 EPSS 0.34%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2023-02-14 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2023-23851
Severity
MEDIUM
CVSS
5.4
EPSS
0.34%

Original NVD Description

SAP Business Planning and Consolidation - versions 200, 300, allows an attacker with business authorization to upload any files (including web pages) without the proper file format validation. If other users visit the uploaded malicious web page, the attacker may perform actions on behalf of the users without their consent impacting the confidentiality and integrity of the system.