Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-33692

Опубликовано: 15 сент. 2021
Источник: nvd
CVSS3: 5.2
CVSS3: 7.5
CVSS2: 5
EPSS Низкий

Описание

SAP Cloud Connector, version - 2.0, allows the upload of zip files as backup. This backup file can be tricked to inject special elements such as '..' and '/' separators, for attackers to escape outside of the restricted location to access files or directories.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:sap:cloud_connector:2.0:*:*:*:*:*:*:*

EPSS

Процентиль: 57%
0.0035
Низкий

5.2 Medium

CVSS3

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-22

Связанные уязвимости

github
больше 3 лет назад

SAP Cloud Connector, version - 2.0, allows the upload of zip files as backup. This backup file can be tricked to inject special elements such as '..' and '/' separators, for attackers to escape outside of the restricted location to access files or directories.

EPSS

Процентиль: 57%
0.0035
Низкий

5.2 Medium

CVSS3

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-22