CVE-2023-50422Critical· 9.1▾ MidnightImproper Privilege Management in github.com/sap/cloud-security-client-go
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 50.1 · likelihood 0.3 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 9.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
1.4%
SAP BTP Security Services Integration Library ([Golang] github.com/sap/cloud-security-client-go) allows under certain conditions an escalation of privileges. On successful exploitation, an unauthenticated attacker can obtain arbitrary permissions within the application.
Upgrade to patched version >= 0.17.0 We always recommend to upgrade to the latest released version.
No workarounds
https://www.cve.org/CVERecord?id=CVE-2023-50424
github.com/sap/cloud-security-client-go < 0.17.0Upgrade to a patched release:
github.com/sap/cloud-security-client-go 0.17.0Connected by shared product, vendor, weakness, or advisory.
CVE-2022-35293Critical· 9.1Due to insecure session management, SAP Enable Now allows an unauthenticated attacker to gain access to user's account
CVE-2026-66778Medium· 5.3SAP Approuter does not sufficiently sanitize certain request headers before forwarding traffic to internal components
CVE-2026-66777Medium· 5.9SAP Approuter does not sufficiently validate certain incoming requests before forwarding them to backend destinations
CVE-2026-66776Medium· 5.9SAP Approuter does not consistently enforce integrity verification on certain session-related request headers under specific conditions
CVE-2026-66775Medium· 4.3SAP Approuter does not enforce cross-site request forgery protection on the authentication flow by default
CVE-2026-66774Low· 3.7SAP Approuter does not consistently handle certain error conditions