Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-29186

Опубликовано: 11 апр. 2023
Источник: nvd
CVSS3: 8.7
CVSS3: 6.5
EPSS Средний

Описание

In SAP NetWeaver (BI CONT ADDON) - versions 707, 737, 747, 757, an attacker can exploit a directory traversal flaw in a report to upload and overwrite files on the SAP server. Data cannot be read but if a remote attacker has sufficient (administrative) privileges then potentially critical OS files can be overwritten making the system unavailable.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:sap:netweaver:707:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver:737:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver:747:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver:757:*:*:*:*:*:*:*

EPSS

Процентиль: 96%
0.22137
Средний

8.7 High

CVSS3

6.5 Medium

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 6.5
github
больше 2 лет назад

In SAP NetWeaver (BI CONT ADDON) - versions 707, 737, 747, 757, an attacker can exploit a directory traversal flaw in a report to upload and overwrite files on the SAP server. Data cannot be read but if a remote attacker has sufficient (administrative) privileges then potentially critical OS files can be overwritten making the system unavailable.

EPSS

Процентиль: 96%
0.22137
Средний

8.7 High

CVSS3

6.5 Medium

CVSS3

Дефекты

CWE-22