Directory Traversal Vulnerability in SAP Master Data Management
CVE-2021-21475

6.8MEDIUM

Key Information:

Vendor
SAP
Vendor
CVE Published:
9 February 2021

Summary

The directory traversal vulnerability in SAP Master Data Management allows unauthorized users to manipulate path information due to insufficient validation. This exploitation may permit attackers to traverse directory structures using special characters, ultimately granting access to sensitive files on the server, thereby risking data confidentiality.

Affected Version(s)

SAP NetWeaver Master Data Management Server < 710 < 710

SAP NetWeaver Master Data Management Server < 710.750 < 710.750

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.