SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2003-0748

Directory traversal vulnerability in wgate.dll for SAP Internet Transaction Server (ITS) 4620.2.0.323011 allows remote attackers to read arbitrary files via ..\ (dot-dot backslash) sequences in the ~theme parameter and a ~template parameter with a…

MEDIUM 5.0EPSS 8.05%

Does this matter?

Lower severity and a low EPSS score (8.05%). Track it; it rarely justifies an emergency change on its own.

Description

Directory traversal vulnerability in wgate.dll for SAP Internet Transaction Server (ITS) 4620.2.0.323011 allows remote attackers to read arbitrary files via ..\ (dot-dot backslash) sequences in the ~theme parameter and a ~template parameter with a filename followed by space characters, which can prevent SAP from effectively adding a .html extension to the filename.

CVSS 2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS
8.05% probability · 94th percentile
CISA KEV
Not listed
Affected
sap/internet transaction server
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.