CRITICAL 9.1 Maven

Improper JWT Signature Validation in SAP Security Services Library

GHSA-59c9-pxq8-9c73 · CVE-2023-50422 · CVE-2023-50424 · GHSA-92cg-ghq6-9587 · GHSA-m8rw-rcpq-2vp2 · GO-2023-2400

Published · Modified

Description

Impact

SAP BTP Security Services Integration Library ([Java] cloud-security-services-integration-library) allows under certain conditions an escalation of privileges. On successful exploitation, an unauthenticated attacker can obtain arbitrary permissions within the application.

Patches

Upgrade to patched version >= 2.17.0 or >= 3.3.0
We always recommend to upgrade to the latest released version.

Workarounds

No workarounds

References

https://www.cve.org/CVERecord?id=CVE-2023-50422

Ready to move

Start Securing

Free, no credit card | First findings in minutes