Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-63626
HistoryMar 25, 2022 - 12:00 a.m.

SAP Cloud Connector Path Traversal Vulnerability

2022-03-2500:00:00
China National Vulnerability Database
www.cnvd.org.cn
9

0.003 Low

EPSS

Percentile

71.6%

SAP Cloud Connector is used to establish a secure connection between a computer and the SAP Cloud Platform. SAP Cloud Connector version 2.0 is vulnerable to a path traversal vulnerability that arises from allowing zip files to be uploaded as backups. Such backup files can be spoofed to inject special elements, such as ‘…’ and the ‘/’ separator, which can be exploited by an attacker to inject code to access files or directories via path traversal.

CPENameOperatorVersion
sap cloud connectoreq2.0

0.003 Low

EPSS

Percentile

71.6%

Related for CNVD-2022-63626