Directory Traversal vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform
CVE-2023-27500

8.1HIGH

Key Information:

Vendor
SAP
Vendor
CVE Published:
14 March 2023

Summary

An attacker with non-administrative permissions may exploit a directory traversal vulnerability in SAPRSBRO to overwrite critical operating system files. This attack compromises system file integrity, potentially resulting in system availability issues, although no data can be read in the process. It highlights the importance of applying security updates to safeguard against such vulnerabilities.

Affected Version(s)

NetWeaver AS for ABAP and ABAP Platform (SAPRSBRO Program) 700

NetWeaver AS for ABAP and ABAP Platform (SAPRSBRO Program) 701

NetWeaver AS for ABAP and ABAP Platform (SAPRSBRO Program) 702

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.