Medium severity4.2NVD Advisory· Published Jun 13, 2023· Updated Jun 17, 2026
CVE-2023-32115
CVE-2023-32115
Description
An attacker can exploit MDS COMPARE TOOL and use specially crafted inputs to read and modify database commands, resulting in the retrieval of additional information persisted by the system.
Affected products
9cpe:2.3:a:sap:master_data_synchronization:600:*:*:*:*:*:*:*+ 7 more
- cpe:2.3:a:sap:master_data_synchronization:600:*:*:*:*:*:*:*
- cpe:2.3:a:sap:master_data_synchronization:602:*:*:*:*:*:*:*
- cpe:2.3:a:sap:master_data_synchronization:603:*:*:*:*:*:*:*
- cpe:2.3:a:sap:master_data_synchronization:604:*:*:*:*:*:*:*
- cpe:2.3:a:sap:master_data_synchronization:605:*:*:*:*:*:*:*
- cpe:2.3:a:sap:master_data_synchronization:606:*:*:*:*:*:*:*
- cpe:2.3:a:sap:master_data_synchronization:616:*:*:*:*:*:*:*
- (no CPE)range: SAP_APPL 600
Patches
Vulnerability mechanics
References
2- www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.htmlnvdVendor Advisory
- launchpad.support.sap.comnvdPermissions Required
News mentions
0No linked articles in our index yet.