CVE-2023-49058

SAP Master Data Governance File Upload application allows an attacker to exploit insufficient validation of path information provided by users, thus characters representing ‘traverse to parent directory’ are passed through to the file APIs. As a result, it has a low impact to the confidentiality.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:sap:master_data_governance:731:*:*:*:*:*:*:*
cpe:2.3:a:sap:master_data_governance:732:*:*:*:*:*:*:*
cpe:2.3:a:sap:master_data_governance:746:*:*:*:*:*:*:*
cpe:2.3:a:sap:master_data_governance:747:*:*:*:*:*:*:*
cpe:2.3:a:sap:master_data_governance:748:*:*:*:*:*:*:*
cpe:2.3:a:sap:master_data_governance:749:*:*:*:*:*:*:*
cpe:2.3:a:sap:master_data_governance:751:*:*:*:*:*:*:*
cpe:2.3:a:sap:master_data_governance:752:*:*:*:*:*:*:*
cpe:2.3:a:sap:master_data_governance:800:*:*:*:*:*:*:*
cpe:2.3:a:sap:master_data_governance:801:*:*:*:*:*:*:*
cpe:2.3:a:sap:master_data_governance:802:*:*:*:*:*:*:*
cpe:2.3:a:sap:master_data_governance:803:*:*:*:*:*:*:*
cpe:2.3:a:sap:master_data_governance:804:*:*:*:*:*:*:*
cpe:2.3:a:sap:master_data_governance:805:*:*:*:*:*:*:*
cpe:2.3:a:sap:master_data_governance:806:*:*:*:*:*:*:*
cpe:2.3:a:sap:master_data_governance:807:*:*:*:*:*:*:*
cpe:2.3:a:sap:master_data_governance:808:*:*:*:*:*:*:*

History

14 Dec 2023, 18:56

Type Values Removed Values Added
New CVE

Information

Published : 2023-12-12 01:15

Updated : 2024-02-28 20:54


NVD link : CVE-2023-49058

Mitre link : CVE-2023-49058

CVE.ORG link : CVE-2023-49058


JSON object : View

Products Affected

sap

  • master_data_governance
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')