Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7w9p-pr7x-mjw2

Опубликовано: 24 апр. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 10

Описание

SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries that could severely harm the host system. This could significantly affect the confidentiality, integrity, and availability of the targeted system.

SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries that could severely harm the host system. This could significantly affect the confidentiality, integrity, and availability of the targeted system.

EPSS

Процентиль: 97%
0.33314
Средний

10 Critical

CVSS3

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 10
nvd
10 месяцев назад

SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries that could severely harm the host system. This could significantly affect the confidentiality, integrity, and availability of the targeted system.

CVSS3: 10
fstec
10 месяцев назад

Уязвимость функции MetadataUploader инструмента Visual Composer программной интеграционной платформы SAP NetWeaver, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 97%
0.33314
Средний

10 Critical

CVSS3

Дефекты

CWE-434