SAP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 791, allows an attacker with non-administrative authorizations to exploit a directory traversal flaw in an available service to overwrite the system files. In this attack, no data can be read but potentially critical OS files can be overwritten making the system unavailable.
References
Link | Resource |
---|---|
https://launchpad.support.sap.com/#/notes/3294595 | Permissions Required |
https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html | Vendor Advisory |
https://launchpad.support.sap.com/#/notes/3294595 | Permissions Required |
https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 07:52
Type | Values Removed | Values Added |
---|---|---|
References | () https://launchpad.support.sap.com/#/notes/3294595 - Permissions Required | |
References | () https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html - Vendor Advisory |
Information
Published : 2023-03-14 05:15
Updated : 2024-11-21 07:52
NVD link : CVE-2023-27269
Mitre link : CVE-2023-27269
CVE.ORG link : CVE-2023-27269
JSON object : View
Products Affected
sap
- netweaver_application_server_abap
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')