PT-2024-2957 · Sap · Sap Asset Accounting

Published

2024-04-08

·

Updated

2024-04-09

·

CVE-2024-27901

CVSS v2.0

8.3

High

VectorAV:N/AC:L/Au:M/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions SAP Asset Accounting (affected versions not specified)
Description The issue is related to insufficient validation of path information provided by users, which can be exploited by a high-privileged attacker to impact the confidentiality, integrity, and availability of the application. This can be achieved by passing the path information through to the file API's. The exploitation may involve a specially crafted HTML page.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

BDU:2024-03124
CVE-2024-27901

Affected Products

Sap Asset Accounting