CVE-2023-49058

SAP Master Data Governance File Upload applicationallows an attacker to exploit insufficient validation of path information provided by users, thus characters representing traverse to parent directory are passed through to the fileAPIs. As a result, it has a low impact to theconfidentiality.

Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
3.5 LOW
NETWORK
HIGH
LOW
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N
sapCNA
3.5 LOW
NETWORK
HIGH
LOW
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N
CVEADP
---
---