Directory Traversal Vulnerability in SAP Focused Run by SAP
CVE-2022-27657
2.7LOW
Key Information:
- Vendor
- SAP
- Vendor
- CVE Published:
- 12 April 2022
Summary
A directory traversal vulnerability exists in SAP Focused Run's Simple Diagnostics Agent 1.0, allowing a remote attacker with high privileges to exploit insufficient path validation. This exploitation enables unauthorized access to restricted directories, potentially exposing sensitive information. Timely updates and patch management are essential to mitigate this risk.
Affected Version(s)
SAP Focused Run (Simple Diagnostics Agent) 1.0
References
CVSS V3.1
Score:
2.7
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved