CVE-2003-0748
Directory traversal vulnerability in wgate.dll for SAP Internet Transaction Server (ITS) 4620.2.0.323011 allows remote attackers to read arbitrary files via ..\ (dot-dot backslash) sequences in the ~theme parameter and a ~template parameter with a…
Does this matter?
Lower severity and a low EPSS score (8.05%). Track it; it rarely justifies an emergency change on its own.
Description
Directory traversal vulnerability in wgate.dll for SAP Internet Transaction Server (ITS) 4620.2.0.323011 allows remote attackers to read arbitrary files via ..\ (dot-dot backslash) sequences in the ~theme parameter and a ~template parameter with a filename followed by space characters, which can prevent SAP from effectively adding a .html extension to the filename.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 8.05% probability · 94th percentile
- CISA KEV
- Not listed
- Affected
- sap/internet transaction server
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/bugtraq/2003-08/0361.htmlExploit, Vendor Advisory
- http://www.securityfocus.com/bid/8516Exploit, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/13066
- http://archives.neohapsis.com/archives/bugtraq/2003-08/0361.htmlExploit, Vendor Advisory
- http://www.securityfocus.com/bid/8516Exploit, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/13066
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.