CVE-2023-0023
Description
In SAP Bank Account Management (Manage Banks) application, when a user clicks a smart link to navigate to another app, personal data is shown directly in the URL. They might get captured in log files, bookmarks, and so on disclosing sensitive data of the application.
- CVSS Version 3.1
nvd
CVE ID: CVE-2023-0023
Base Score: 5.7
Base Severity: MEDIUM
Vector String:CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
Impact Score: 3.6
Exploitability Score: 2.1
sap
CVE ID: CVE-2023-0023
Base Score: 4.5
Base Severity: MEDIUM
Vector String:CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N
Impact Score: 3.6
Exploitability Score: 0.9