CVE-2023-35870 is a vulnerability in SAP S/4HANA (S4CORE versions 104-107) that allows an unauthenticated attacker to intercept and alter journal entry templates during the save process. This could lead to unauthorized modification or disclosure of template data, and potentially the deletion of standard templates, causing temporary service unavailability. With a CVSS score of 7.3 (High), it has a low attack complexity and requires no user interaction, impacting confidentiality, integrity, and availability. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
104CPE matchmatch criteria | cpe:2.3:a:sap:s4core:104:*:*:*:*:*:*:* | ||
105CPE matchmatch criteria | cpe:2.3:a:sap:s4core:105:*:*:*:*:*:*:* | ||
106CPE matchmatch criteria | cpe:2.3:a:sap:s4core:106:*:*:*:*:*:*:* | ||
107CPE matchmatch criteria | cpe:2.3:a:sap:s4core:107:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.