Directory Traversal Vulnerability in SAP Focused Run by SAP
CVE-2022-27657

2.7LOW

Key Information:

Vendor
SAP
Vendor
CVE Published:
12 April 2022

Summary

A directory traversal vulnerability exists in SAP Focused Run's Simple Diagnostics Agent 1.0, allowing a remote attacker with high privileges to exploit insufficient path validation. This exploitation enables unauthorized access to restricted directories, potentially exposing sensitive information. Timely updates and patch management are essential to mitigate this risk.

Affected Version(s)

SAP Focused Run (Simple Diagnostics Agent) 1.0

References

CVSS V3.1

Score:
2.7
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.