SAP Plant Connectivity - version 15.5 (PCo) or the Production Connector for SAP Digital Manufacturing - version 1.0, do not validate the signature of the JSON Web Token (JWT) in the HTTP request sent from SAP Digital Manufacturing. Therefore, unauthorized callers from the internal network could send service requests to PCo or the Production Connector, which could have an impact on the integrity of the integration with SAP Digital Manufacturing.
Metrics
Affected Vendors & Products
References
History
Fri, 03 Jan 2025 02:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|

Status: PUBLISHED
Assigner: sap
Published:
Updated: 2025-01-03T02:07:52.209Z
Reserved: 2023-05-22T06:34:19.652Z
Link: CVE-2023-2827

Updated: 2024-08-02T06:33:05.830Z

Status : Modified
Published: 2023-06-13T03:15:09.223
Modified: 2024-11-21T07:59:22.017
Link: CVE-2023-2827

No data.