Directory Traversal vulnerability in SAP Master Data Governance
CVE-2023-49058

3.5LOW

Key Information:

Vendor
SAP
Vendor
CVE Published:
12 December 2023

Summary

SAP Master Data Governance File Upload application allows an attacker to exploit insufficient validation of path information provided by users, thus characters representing ‘traverse to parent directory’ are passed through to the file APIs. As a result, it has a low impact to the confidentiality.

Affected Version(s)

SAP Master Data Governance MDG_FND 731

SAP Master Data Governance MDG_FND 732

SAP Master Data Governance MDG_FND 746

References

CVSS V3.1

Score:
3.5
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.