CVE-2023-0023

Severity CVSS v4.0:
Pending analysis
Type:
CWE-200 Information Leak / Disclosure
Publication date:
10/01/2023
Last modified:
13/01/2023

Description

In SAP Bank Account Management (Manage Banks) application, when a user clicks a smart link to navigate to another app, personal data is shown directly in the URL. They might get captured in log files, bookmarks, and so on disclosing sensitive data of the application.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:sap:bank_account_management:800:*:*:*:*:*:*:*
cpe:2.3:a:sap:bank_account_management:900:*:*:*:*:*:*:*