Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rc4p-33hg-59pr

Опубликовано: 08 апр. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 7.7

Описание

Due to directory traversal vulnerability, an authorized attacker could gain access to some critical information by using RFC enabled function module. Upon successful exploitation, they could read files from any managed system connected to SAP Solution Manager, leading to high impact on confidentiality. There is no impact on integrity or availability.

Due to directory traversal vulnerability, an authorized attacker could gain access to some critical information by using RFC enabled function module. Upon successful exploitation, they could read files from any managed system connected to SAP Solution Manager, leading to high impact on confidentiality. There is no impact on integrity or availability.

EPSS

Процентиль: 44%
0.00591
Низкий

7.7 High

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 7.7
nvd
больше 1 года назад

Due to directory traversal vulnerability, an authorized attacker could gain access to some critical information by using RFC enabled function module. Upon successful exploitation, they could read files from any managed system connected to SAP Solution Manager, leading to high impact on confidentiality. There is no impact on integrity or availability.

CVSS3: 7.7
fstec
больше 1 года назад

Уязвимость компонента RFC Enabled Function Module программных интеграционных платформ SAP NetWeaver и ABAP Platform, связанная с недостатками процедуры авторизации, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 44%
0.00591
Низкий

7.7 High

CVSS3

Дефекты

CWE-862