Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-21475

Опубликовано: 09 фев. 2021
Источник: nvd
CVSS3: 6.8
CVSS3: 7.5
CVSS2: 5
EPSS Низкий

Описание

Under specific circumstances SAP Master Data Management, versions - 710, 710.750, allows an unauthorized attacker to exploit insufficient validation of path information provided by users, thus characters representing 'traverse to parent directory' are passed through to the file APIs. Due to this Directory Traversal vulnerability the attacker could read content of arbitrary files on the remote server and expose sensitive data.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:sap:netweaver_master_data_management_server:710:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_master_data_management_server:710.750:*:*:*:*:*:*:*

EPSS

Процентиль: 67%
0.00534
Низкий

6.8 Medium

CVSS3

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-22

Связанные уязвимости

github
больше 3 лет назад

Under specific circumstances SAP Master Data Management, versions - 710, 710.750, allows an unauthorized attacker to exploit insufficient validation of path information provided by users, thus characters representing 'traverse to parent directory' are passed through to the file APIs. Due to this Directory Traversal vulnerability the attacker could read content of arbitrary files on the remote server and expose sensitive data.

EPSS

Процентиль: 67%
0.00534
Низкий

6.8 Medium

CVSS3

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-22