ID

VAR-201311-0369


CVE

CVE-2013-6823


TITLE

SAP NetWeaver GRMGApp Security Bypass and Information Disclosure Vulnerabilities

Trust: 0.9

sources: BID: 58095 // CNNVD: CNNVD-201302-484

DESCRIPTION

GRMGApp in SAP NetWeaver allows remote attackers to bypass intended access restrictions via unspecified vectors. SAP NetWeaver is prone to a security-bypass vulnerability and an information-disclosure vulnerability. Successful exploits may allow an attacker to obtain sensitive information or bypass certain security restrictions and perform unauthorized actions. This may aid in further attacks

Trust: 1.89

sources: NVD: CVE-2013-6823 // JVNDB: JVNDB-2013-005202 // BID: 58095

AFFECTED PRODUCTS

vendor:sapmodel:netweaverscope:eqversion: -

Trust: 1.6

vendor:sapmodel:netweaverscope: - version: -

Trust: 0.8

vendor:sapmodel:netweaverscope:eqversion:7.30

Trust: 0.3

vendor:sapmodel:netweaverscope:eqversion:7.10

Trust: 0.3

vendor:sapmodel:netweaverscope:eqversion:7.02

Trust: 0.3

vendor:sapmodel:netweaverscope:eqversion:7.01

Trust: 0.3

vendor:sapmodel:netweaverscope:eqversion:7.0

Trust: 0.3

sources: BID: 58095 // JVNDB: JVNDB-2013-005202 // CNNVD: CNNVD-201311-294 // NVD: CVE-2013-6823

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2013-6823
value: MEDIUM

Trust: 1.0

NVD: CVE-2013-6823
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-201311-294
value: MEDIUM

Trust: 0.6

nvd@nist.gov: CVE-2013-6823
severity: MEDIUM
baseScore: 6.4
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 4.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

sources: JVNDB: JVNDB-2013-005202 // CNNVD: CNNVD-201311-294 // NVD: CVE-2013-6823

PROBLEMTYPE DATA

problemtype:CWE-264

Trust: 1.8

sources: JVNDB: JVNDB-2013-005202 // NVD: CVE-2013-6823

THREAT TYPE

remote

Trust: 1.2

sources: CNNVD: CNNVD-201311-294 // CNNVD: CNNVD-201302-484

TYPE

permissions and access control

Trust: 0.6

sources: CNNVD: CNNVD-201311-294

CONFIGURATIONS

sources: JVNDB: JVNDB-2013-005202

PATCH

title:Acknowledgments to Security Researchersurl:http://scn.sap.com/docs/DOC-8218

Trust: 0.8

sources: JVNDB: JVNDB-2013-005202

EXTERNAL IDS

db:NVDid:CVE-2013-6823

Trust: 2.7

db:BIDid:58095

Trust: 0.9

db:JVNDBid:JVNDB-2013-005202

Trust: 0.8

db:CNNVDid:CNNVD-201311-294

Trust: 0.6

db:CNNVDid:CNNVD-201302-484

Trust: 0.6

sources: BID: 58095 // JVNDB: JVNDB-2013-005202 // CNNVD: CNNVD-201311-294 // CNNVD: CNNVD-201302-484 // NVD: CVE-2013-6823

REFERENCES

url:http://scn.sap.com/docs/doc-8218

Trust: 1.6

url:http://erpscan.com/advisories/dsecrg-13-002-sap-grmgapp-xxe-and-authentication-bypass/

Trust: 1.4

url:https://erpscan.io/advisories/dsecrg-13-002-sap-grmgapp-xxe-and-authentication-bypass/

Trust: 1.0

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2013-6823

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2013-6823

Trust: 0.8

url:http://www.securityfocus.com/bid/58095

Trust: 0.6

url:http://www.sap.com/platform/netweaver/index.epx

Trust: 0.3

sources: BID: 58095 // JVNDB: JVNDB-2013-005202 // CNNVD: CNNVD-201311-294 // CNNVD: CNNVD-201302-484 // NVD: CVE-2013-6823

CREDITS

Dmitry Chastukhin of ERPScan

Trust: 0.9

sources: BID: 58095 // CNNVD: CNNVD-201302-484

SOURCES

db:BIDid:58095
db:JVNDBid:JVNDB-2013-005202
db:CNNVDid:CNNVD-201311-294
db:CNNVDid:CNNVD-201302-484
db:NVDid:CVE-2013-6823

LAST UPDATE DATE

2024-11-23T22:18:43.390000+00:00


SOURCES UPDATE DATE

db:BIDid:58095date:2013-11-25T01:04:00
db:JVNDBid:JVNDB-2013-005202date:2013-11-21T00:00:00
db:CNNVDid:CNNVD-201311-294date:2013-11-22T00:00:00
db:CNNVDid:CNNVD-201302-484date:2013-02-26T00:00:00
db:NVDid:CVE-2013-6823date:2024-11-21T01:59:46.720

SOURCES RELEASE DATE

db:BIDid:58095date:2013-01-28T00:00:00
db:JVNDBid:JVNDB-2013-005202date:2013-11-21T00:00:00
db:CNNVDid:CNNVD-201311-294date:2013-11-22T00:00:00
db:CNNVDid:CNNVD-201302-484date:2013-01-28T00:00:00
db:NVDid:CVE-2013-6823date:2013-11-20T14:12:31.037