CVE-2023-49058
CVSS V2 None
CVSS V3 None
Description
SAP Master Data Governance File Upload application allows an attacker to exploit insufficient validation of path information provided by users, thus characters representing ‘traverse to parent directory’ are passed through to the file APIs. As a result, it has a low impact to the confidentiality.
Overview
- CVE ID
- CVE-2023-49058
- Assigner
- sap
- Vulnerability Status
- PUBLISHED
- Published Version
- 2023-12-12T01:01:07.964Z
- Last Modified Date
- 2023-12-12T01:01:07.964Z
Weakness Enumerations
References
Reference URL | Reference Tags |
---|---|
https://me.sap.com/notes/3363690 | |
https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2023-49058 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-49058 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-06-25 13:28:26 | Added to TrackCVE |