CRITICAL🇵🇱 Wersja polska

CVE-2023-27269

CVSS 9.6v3.1pub. 2023-03-14upd. 2024-11-21

SAP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 791, allows an attacker with non-administrative authorizations to exploit a directory traversal flaw in an available service to overwrite the system files.  In this attack, no data can be read but potentially critical OS files can be overwritten making the system unavailable.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H
  • Sap Netweaver Application Server Abap

    APP
    Sap
    700701702731740750751752753754755756757791
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Path Traversal
CWE
References

Related vulnerabilities

CVE-2022-22536CRITICAL10.0⚠ KEVPL ✓same product

Request Smuggling w SAP NetWeaver i SAP Web Dispatcher — CVSS 10.0

CVE-2026-0488CRITICAL9.9PL ✓same product

SAP CRM / S/4HANA Scripting Editor — nieautoryzowane wykonanie SQL

CVE-2023-40309CRITICAL9.8PL ✓same product

SAP CommonCryptoLib — brak weryfikacji autoryzacji, privilege escalation

CVE-2023-27500CRITICAL9.6PL ✓same product

SAP NetWeaver AS ABAP: path traversal w SAPRSBRO umożliwia nadpisanie plików systemowych

CVE-2023-0014CRITICAL9.0PL ✓same product

SAP NetWeaver ABAP – podatność capture-replay umożliwiająca nieautoryzowany dostęp