PT-2020-19004 · Sap · Sap Netweaver Uddi Server

Published

2020-03-10

·

Updated

2020-03-12

·

CVE-2020-6203

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SAP NetWeaver UDDI Server (Services Registry) versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50
Description The issue allows an attacker to exploit insufficient validation of path information provided by users. This leads to Path Traversal, as characters representing 'traverse to parent directory' are passed through to the file APIs.
Recommendations For versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, update to a version that includes the fix for this issue, as no specific mitigation measures are provided for these versions. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-6203

Affected Products

Sap Netweaver Uddi Server