In SAP NetWeaver (BI CONT ADDON) - versions 707, 737, 747, 757, an attacker can exploit a directory traversal flaw in a report to upload and overwrite files on the SAP server. Data cannot be read but if a remote attacker has sufficient (administrative) privileges then potentially critical OS files can be overwritten making the system unavailable.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 07 Feb 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: sap
Published:
Updated: 2025-02-07T17:12:10.486Z
Reserved: 2023-04-03T09:22:43.157Z
Link: CVE-2023-29186
Updated: 2024-08-02T14:00:15.983Z
Status : Modified
Published: 2023-04-11T04:16:08.610
Modified: 2024-11-21T07:56:40.720
Link: CVE-2023-29186
No data.
OpenCVE Enrichment
No data.
Weaknesses