Skip to main content

CVE-2023-0023

Description

In SAP Bank Account Management (Manage Banks) application, when a user clicks a smart link to navigate to another app, personal data is shown directly in the URL. They might get captured in log files, bookmarks, and so on disclosing sensitive data of the application.

nvd
CVE ID: CVE-2023-0023
Base Score: 5.7
Base Severity: MEDIUM
Vector String:CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
Impact Score: 3.6
Exploitability Score: 2.1
sap
CVE ID: CVE-2023-0023
Base Score: 4.5
Base Severity: MEDIUM
Vector String:CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N
Impact Score: 3.6
Exploitability Score: 0.9

Refrence: NVDMITRE