{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2023-50422","assignerOrgId":"e4686d1a-f260-4930-ac4c-2f5c992778dd","state":"PUBLISHED","assignerShortName":"sap","dateReserved":"2023-12-09T17:19:02.677Z","datePublished":"2023-12-12T01:31:17.991Z","dateUpdated":"2026-02-25T16:34:36.244Z"},"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"cloud-security-services-integration-library","vendor":"SAP_SE","versions":[{"status":"affected","version":"< 2.17.0"},{"lessThan":"3.3.0","status":"affected","version":"3.0.0","versionType":"custom"}]}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>SAP BTP Security Services Integration Library ([Java] cloud-security-services-integration-library) - versions below 2.17.0 and versions from 3.0.0 to before 3.3.0, allow under certain conditions an escalation of privileges. On successful exploitation, an unauthenticated attacker can obtain arbitrary permissions within the application.</p>"}],"value":"SAP BTP Security Services Integration Library ([Java] cloud-security-services-integration-library) - versions below 2.17.0 and versions from 3.0.0 to before 3.3.0, allow under certain conditions an escalation of privileges. On successful exploitation, an unauthenticated attacker can obtain arbitrary permissions within the application."}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":9.1,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-749","description":"CWE-749: Exposed Dangerous Method or Function","lang":"en","type":"CWE"}]}],"providerMetadata":{"orgId":"e4686d1a-f260-4930-ac4c-2f5c992778dd","shortName":"sap","dateUpdated":"2024-09-28T22:17:43.519Z"},"references":[{"tags":["vendor-advisory"],"url":"https://me.sap.com/notes/3411067"},{"url":"https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html"},{"url":"https://github.com/SAP/cloud-security-services-integration-library/"},{"url":"https://mvnrepository.com/artifact/com.sap.cloud.security/java-security"},{"url":"https://mvnrepository.com/artifact/com.sap.cloud.security/spring-security"},{"url":"https://mvnrepository.com/artifact/com.sap.cloud.security.xsuaa/spring-xsuaa"},{"url":"https://blogs.sap.com/2023/12/12/unveiling-critical-security-updates-sap-btp-security-note-3411067/"},{"tags":["vendor-advisory"],"url":"https://github.com/SAP/cloud-security-services-integration-library/security/advisories/GHSA-59c9-pxq8-9c73"},{"url":"https://me.sap.com/notes/3413475"}],"source":{"discovery":"UNKNOWN"},"title":"Escalation of Privileges in SAP BTP Security Services Integration Library ([Java] cloud-security-services-integration-library)","x_generator":{"engine":"Vulnogram 0.1.0-dev"}},"adp":[{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-02T22:16:46.536Z"},"title":"CVE Program Container","references":[{"tags":["vendor-advisory","x_transferred"],"url":"https://me.sap.com/notes/3411067"},{"url":"https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html","tags":["x_transferred"]},{"url":"https://github.com/SAP/cloud-security-services-integration-library/","tags":["x_transferred"]},{"url":"https://mvnrepository.com/artifact/com.sap.cloud.security/java-security","tags":["x_transferred"]},{"url":"https://mvnrepository.com/artifact/com.sap.cloud.security/spring-security","tags":["x_transferred"]},{"url":"https://mvnrepository.com/artifact/com.sap.cloud.security.xsuaa/spring-xsuaa","tags":["x_transferred"]},{"url":"https://blogs.sap.com/2023/12/12/unveiling-critical-security-updates-sap-btp-security-note-3411067/","tags":["x_transferred"]},{"tags":["vendor-advisory","x_transferred"],"url":"https://github.com/SAP/cloud-security-services-integration-library/security/advisories/GHSA-59c9-pxq8-9c73"},{"url":"https://me.sap.com/notes/3413475","tags":["x_transferred"]}]},{"metrics":[{"other":{"type":"ssvc","content":{"id":"CVE-2023-50422","role":"CISA Coordinator","options":[{"Exploitation":"none"},{"Automatable":"yes"},{"Technical Impact":"total"}],"version":"2.0.3","timestamp":"2023-12-14T05:00:14.377359Z"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-02-25T16:34:36.244Z"}}]}}