CVE-2021-33692: Path Traversal
SAP Cloud Connector, version - 2.0, allows the upload of zip files as backup. This backup file can be tricked to inject special elements such as '..' and '/' separators, for attackers to escape outside of the restricted location to access files or directories.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2021-33692?
CVE-2021-33692 is classified as a high severity vulnerability with potential for unauthorized file access.
How do I fix CVE-2021-33692?
To mitigate CVE-2021-33692, update SAP Cloud Connector to the latest version that addresses this vulnerability.
What type of attack does CVE-2021-33692 enable?
CVE-2021-33692 allows attackers to exploit file path traversal to access sensitive files or directories.
Is CVE-2021-33692 exploitable remotely?
Yes, CVE-2021-33692 can be exploited remotely if the SAP Cloud Connector is accessible over the network.
What versions of SAP Cloud Connector are affected by CVE-2021-33692?
SAP Cloud Connector version 2.0 is specifically affected by CVE-2021-33692.