Lucene search

K
cve[email protected]CVE-2023-29186
HistoryApr 11, 2023 - 4:16 a.m.

CVE-2023-29186

2023-04-1104:16:08
CWE-22
web.nvd.nist.gov
33
sap
netweaver
directory traversal
file upload
overwrite
cve-2023-29186
security vulnerability

8.7 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:H

6.4 Medium

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

53.1%

In SAP NetWeaver (BI CONT ADDON) - versions 707, 737, 747, 757, an attacker can exploit a directory traversal flaw in a report toΒ upload and overwrite files on the SAP server. Data cannot be read but if a remote attacker has sufficient (administrative) privileges then potentially critical OS files can be overwritten making the system unavailable.

Affected configurations

NVD
Node
sapnetweaverMatch707
OR
sapnetweaverMatch737
OR
sapnetweaverMatch747
OR
sapnetweaverMatch757

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "NetWeaver (BI CONT ADDON)",
    "vendor": "SAP",
    "versions": [
      {
        "status": "affected",
        "version": "707"
      },
      {
        "status": "affected",
        "version": "737"
      },
      {
        "status": "affected",
        "version": "747"
      },
      {
        "status": "affected",
        "version": "757"
      }
    ]
  }
]

8.7 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:H

6.4 Medium

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

53.1%

Related for CVE-2023-29186