AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2023-37491

HIGH · CVSS 7.5 EPSS 0.44%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2023-08-08 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 7.5. See the original NVD description below for full technical details.

CVE
CVE-2023-37491
Severity
HIGH
CVSS
7.5
EPSS
0.44%

Original NVD Description

The ACL (Access Control List) of SAP Message Server - versions KERNEL 7.22, KERNEL 7.53, KERNEL 7.54, KERNEL 7.77, RNL64UC 7.22, RNL64UC 7.22EXT, RNL64UC 7.53, KRNL64NUC 7.22, KRNL64NUC 7.22EXT, can be bypassed in certain conditions, which may enable an authenticated malicious user to enter the network of the SAP systems served by the attacked SAP Message server. This may lead to unauthorized read and write of data as well as rendering the system unavailable.

Related CVEs

Other vulnerabilities affecting the same vendor(s)