SAP Knowledge Base Article - Preview

3485603 - Spring Framework [CVE-2023-20860] and [CVE-2023-20861] vulnerability - SAP ASE

Symptom

Details of a Spring Framework vulnerability were published under CVE-2023-20860 and CVE-2023-20861. 
Are there any impacts on ASE or exposure to this issue in ASE from these CVEs ?
ASE includes spring files under RMA and AMC.

[RMA]
$SYBASE/DM/RMA-16_0/libs/spring/spring-beans-5.3.13.jar
$SYBASE/DM/RMA-16_0/libs/spring/spring-core-5.3.13.jar

[AMC]
BOOT-INF/lib/spring-core-5.3.19.jar


Read more...

Environment

  • SAP Adaptive Server Enterprise (ASE) 16.0
  • Spring Framework

Product

SAP Adaptive Server Enterprise 16.0

Keywords

CVE-2023-20860, CVE-2023-20861, CVE, ASE, CVE 2023 20860, CVE 2023 20861, Spring Framework , KBA , BC-SYB-ASE , Sybase ASE Database Platform (non Business Suite) , BC-DB-SYB , Business Suite on Adaptive Server Enterprise , Problem

About this page

This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).

Search for additional results

Visit SAP Support Portal's SAP Notes and KBA Search.