CVE-2023-49058

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
12/12/2023
Last modified:
14/12/2023

Description

SAP Master Data Governance File Upload application allows an attacker to exploit insufficient validation of path information provided by users, thus characters representing ‘traverse to parent directory’ are passed through to the file APIs. As a result, it has a low impact to the confidentiality.<br /> <br />

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:sap:master_data_governance:731:*:*:*:*:*:*:*
cpe:2.3:a:sap:master_data_governance:732:*:*:*:*:*:*:*
cpe:2.3:a:sap:master_data_governance:746:*:*:*:*:*:*:*
cpe:2.3:a:sap:master_data_governance:747:*:*:*:*:*:*:*
cpe:2.3:a:sap:master_data_governance:748:*:*:*:*:*:*:*
cpe:2.3:a:sap:master_data_governance:749:*:*:*:*:*:*:*
cpe:2.3:a:sap:master_data_governance:751:*:*:*:*:*:*:*
cpe:2.3:a:sap:master_data_governance:752:*:*:*:*:*:*:*
cpe:2.3:a:sap:master_data_governance:800:*:*:*:*:*:*:*
cpe:2.3:a:sap:master_data_governance:801:*:*:*:*:*:*:*
cpe:2.3:a:sap:master_data_governance:802:*:*:*:*:*:*:*
cpe:2.3:a:sap:master_data_governance:803:*:*:*:*:*:*:*
cpe:2.3:a:sap:master_data_governance:804:*:*:*:*:*:*:*
cpe:2.3:a:sap:master_data_governance:805:*:*:*:*:*:*:*
cpe:2.3:a:sap:master_data_governance:806:*:*:*:*:*:*:*