CVE-2023-49058

SAP Master Data Governance File Upload application allows an attacker to exploit insufficient validation of path information provided by users, thus characters representing ‘traverse to parent directory’ are passed through to the file APIs. As a result, it has a low impact to the confidentiality.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:sap:master_data_governance:749:*:*:*:*:*:*:*
cpe:2.3:a:sap:master_data_governance:751:*:*:*:*:*:*:*
cpe:2.3:a:sap:master_data_governance:752:*:*:*:*:*:*:*
cpe:2.3:a:sap:master_data_governance:800:*:*:*:*:*:*:*
cpe:2.3:a:sap:master_data_governance:801:*:*:*:*:*:*:*
cpe:2.3:a:sap:master_data_governance:802:*:*:*:*:*:*:*
cpe:2.3:a:sap:master_data_governance:803:*:*:*:*:*:*:*
cpe:2.3:a:sap:master_data_governance:804:*:*:*:*:*:*:*
cpe:2.3:a:sap:master_data_governance:748:*:*:*:*:*:*:*
cpe:2.3:a:sap:master_data_governance:731:*:*:*:*:*:*:*
cpe:2.3:a:sap:master_data_governance:732:*:*:*:*:*:*:*
cpe:2.3:a:sap:master_data_governance:746:*:*:*:*:*:*:*
cpe:2.3:a:sap:master_data_governance:747:*:*:*:*:*:*:*
cpe:2.3:a:sap:master_data_governance:805:*:*:*:*:*:*:*
cpe:2.3:a:sap:master_data_governance:806:*:*:*:*:*:*:*
cpe:2.3:a:sap:master_data_governance:807:*:*:*:*:*:*:*
cpe:2.3:a:sap:master_data_governance:808:*:*:*:*:*:*:*

History

14 Dec 2023, 18:56

Type Values Removed Values Added
First Time Sap
Sap master Data Governance
References () https://me.sap.com/notes/3363690 - () https://me.sap.com/notes/3363690 - Permissions Required
References () https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html - () https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html - Vendor Advisory
CPE cpe:2.3:a:sap:master_data_governance:808:*:*:*:*:*:*:*
cpe:2.3:a:sap:master_data_governance:731:*:*:*:*:*:*:*
cpe:2.3:a:sap:master_data_governance:752:*:*:*:*:*:*:*
cpe:2.3:a:sap:master_data_governance:801:*:*:*:*:*:*:*
cpe:2.3:a:sap:master_data_governance:748:*:*:*:*:*:*:*
cpe:2.3:a:sap:master_data_governance:800:*:*:*:*:*:*:*
cpe:2.3:a:sap:master_data_governance:732:*:*:*:*:*:*:*
cpe:2.3:a:sap:master_data_governance:746:*:*:*:*:*:*:*
cpe:2.3:a:sap:master_data_governance:749:*:*:*:*:*:*:*
cpe:2.3:a:sap:master_data_governance:804:*:*:*:*:*:*:*
cpe:2.3:a:sap:master_data_governance:802:*:*:*:*:*:*:*
cpe:2.3:a:sap:master_data_governance:805:*:*:*:*:*:*:*
cpe:2.3:a:sap:master_data_governance:751:*:*:*:*:*:*:*
cpe:2.3:a:sap:master_data_governance:747:*:*:*:*:*:*:*
cpe:2.3:a:sap:master_data_governance:803:*:*:*:*:*:*:*
cpe:2.3:a:sap:master_data_governance:806:*:*:*:*:*:*:*
cpe:2.3:a:sap:master_data_governance:807:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.3

12 Dec 2023, 01:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-12-12 01:15

Updated : 2023-12-14 18:56


NVD link : CVE-2023-49058

Mitre link : CVE-2023-49058


JSON object : View

Products Affected

sap

  • master_data_governance
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')