Description
An attacker with non-administrative authorizations in SAP NetWeaver (BI CONT ADD ON) - versions 707, 737, 747, 757, can exploit a directory traversal flaw to over-write system files. Data from confidential files cannot be read but potentially some OS files can be over-written leading to system compromise.

Published: 2023-07-11
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-38113 An attacker with non-administrative authorizations in SAP NetWeaver (BI CONT ADD ON) - versions 707, 737, 747, 757, can exploit a directory traversal flaw to over-write system files. Data from confidential files cannot be read but potentially some OS files can be over-written leading to system compromise.
History

Wed, 23 Oct 2024 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Sap Netweaver Bi Content
cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published:

Updated: 2024-10-23T17:29:51.327Z

Reserved: 2023-05-24T20:41:32.834Z

Link: CVE-2023-33989

cve-icon Vulnrichment

Updated: 2024-08-02T15:54:14.322Z

cve-icon NVD

Status : Modified

Published: 2023-07-11T03:15:09.587

Modified: 2024-11-21T08:06:21.703

Link: CVE-2023-33989

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses