← back
CVE-2023-27501

Directory Traversal vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform

CVSS 8.7 HIGHEPSS 1.0%CWE-22
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 8.7EPSS 1.0%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
14 Mar 2023Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
SAP NetWeaver AS for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 791, allows an attacker to exploit insufficient validation of path information provided by users, thus exploiting a directory traversal flaw in an available service to delete system files. In this attack, no data can be read but potentially critical OS files can be deleted making the system unavailable, causing significant impact on both availability and integrity
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:H

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →