VDB

CISA-2023-27269

CISA-2023-27269 PUBLISHED CVSS 9.6 CRITICAL

Reported by sap · Published March 14, 2023

SAP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 791, allows an attacker with non-administrative authorizations to exploit a directory traversal flaw in an available service to overwrite the system files.  In this attack, no data can be read but potentially critical OS files can be overwritten making the system unavailable.

Risk Scores

CVSS 3.1
9.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H

Affected Products

VendorProductVersions
SAPNetWeaver Application Server for ABAP and ABAP Platform700, 701, 702
SAPNetWeaver Application Server for ABAP and ABAP Platform700, 701, 702

Timeline

  • Mar 14, 2023 CVE Published
  • Feb 27, 2025 CVE Updated

References

Open in Interactive Console →
$ Console Community · 100/wk Open console ›