PT-2023-31040 · Sap · Sap Master Data Governance

Published

2023-12-11

·

Updated

2023-12-14

·

CVE-2023-49058

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions SAP Master Data Governance (affected versions not specified)
Description The issue allows an attacker to exploit insufficient validation of path information provided by users. This can lead to characters representing 'traverse to parent directory' being passed through to the file APIs, resulting in a low impact to confidentiality.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2023-49058

Affected Products

Sap Master Data Governance