SAP SAPCAR does not check the return value of file operations when extracting files, which allows remote attackers to cause a denial of service (program crash) via an invalid file name in an archive file, aka SAP Security Note 2312905.
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HSap Sapcar
APPSapall versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
DoS
References
Related vulnerabilities
CVE-2022-26100CRITICAL9.8PL ✓same product
Niewystarczająca walidacja danych wejściowych w SAP SAPCAR umożliwia RCE
CVE-2017-8852HIGH7.8same product
SAP SAPCAR 721.510 has a Heap Based Buffer Overflow Vulnerability. It could be exploited with a crafted CAR ar...
CVE-2025-42999CRITICAL9.1⚠ KEVPL ✓same vendor
SAP NetWeaver Visual Composer — niebezpieczna deserializacja treści
CVE-2025-31324CRITICAL10.0⚠ KEVPL ✓same vendor
SAP NetWeaver: nieautoryzowany upload plików wykonywalnych w Visual Composer
CVE-2022-22536CRITICAL10.0⚠ KEVPL ✓same vendor
Request Smuggling w SAP NetWeaver i SAP Web Dispatcher — CVSS 10.0