SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2023-49058

SAP Master Data Governance File Upload application allows an attacker to exploit insufficient validation of path information provided by users, thus characters representing ‘traverse to parent directory’ are passed through to the file APIs.

MEDIUM 5.3EPSS 0.63%

Does this matter?

Lower severity and a low EPSS score (0.63%). Track it; it rarely justifies an emergency change on its own.

Description

SAP Master Data Governance File Upload application allows an attacker to exploit insufficient validation of path information provided by users, thus characters representing ‘traverse to parent directory’ are passed through to the file APIs. As a result, it has a low impact to the confidentiality.

CVSS 3.1
5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS
0.63% probability · 48th percentile
CISA KEV
Not listed
Weakness
CWE-22
Affected
sap/master data governance
Source
cna@sap.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.