CVE-2023-27893 - CVE House
Back to Database
Status published High CVE-2023-27893

Arbitrary Code Execution in SAP Solution Manager and ABAP managed systems (ST-PI)

Vulnerability Description

An attacker authenticated as a user with a non-administrative role and a common remote execution authorization in SAP Solution Manager and ABAP managed systems (ST-PI) - versions 2088_1_700, 2008_1_710, 740, can use a vulnerable interface to execute an application function to perform actions which they would not normally be permitted to perform.  Depending on the function executed, the attack can read or modify any user or application data and can make the application unavailable.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-27893

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

Solution Manager and ABAP managed systems
Vulnerable Versions:
2088_1_700, 2008_1_710, 740

Timeline

Official Publish: March 14th, 2023
Last Modified: February 27th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Weaknesses (CWE)