Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-49058


SAP Master Data Governance File Upload application allows an attacker to exploit insufficient validation of path information provided by users, thus characters representing ‘traverse to parent directory’ are passed through to the file APIs. As a result, it has a low impact to the confidentiality.


Published

2023-12-12T01:15:12.840

Last Modified

2024-11-21T08:32:44.870

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 3.5 (LOW)

Weaknesses
  • Type: Primary
    CWE-22

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application sap master_data_governance 731 Yes
Application sap master_data_governance 732 Yes
Application sap master_data_governance 746 Yes
Application sap master_data_governance 747 Yes
Application sap master_data_governance 748 Yes
Application sap master_data_governance 749 Yes
Application sap master_data_governance 751 Yes
Application sap master_data_governance 752 Yes
Application sap master_data_governance 800 Yes
Application sap master_data_governance 801 Yes
Application sap master_data_governance 802 Yes
Application sap master_data_governance 803 Yes
Application sap master_data_governance 804 Yes
Application sap master_data_governance 805 Yes
Application sap master_data_governance 806 Yes
Application sap master_data_governance 807 Yes
Application sap master_data_governance 808 Yes

References