SAP Master Data Governance File Upload application allows an attacker to exploit insufficient validation of path information provided by users, thus characters representing ‘traverse to parent directory’ are passed through to the file APIs. As a result, it has a low impact to the confidentiality.
References
Link | Resource |
---|---|
https://me.sap.com/notes/3363690 | Permissions Required |
https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
14 Dec 2023, 18:56
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-12-12 01:15
Updated : 2024-02-28 20:54
NVD link : CVE-2023-49058
Mitre link : CVE-2023-49058
CVE.ORG link : CVE-2023-49058
JSON object : View
Products Affected
sap
- master_data_governance
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')