PT-2020-19023 · Sap · Sap Netweaver

Published

2020-04-14

·

Updated

2020-04-15

·

CVE-2020-6225

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L
Name of the Vulnerable Software and Affected Versions SAP NetWeaver (Knowledge Management) versions 7.00 through 7.50
Description The issue arises from insufficient validation of path information provided by users, allowing characters that represent a traverse to the parent directory to be passed through to the file APIs. This enables an attacker to overwrite, delete, or corrupt arbitrary files on the remote server, resulting in a path traversal issue.
Recommendations For versions 7.00 through 7.50, update to a version that includes the fix for this issue to prevent path traversal attacks.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-6225

Affected Products

Sap Netweaver