First published: Wed Sep 15 2021(Updated: )
SAP Cloud Connector, version - 2.0, allows the upload of zip files as backup. This backup file can be tricked to inject special elements such as '..' and '/' separators, for attackers to escape outside of the restricted location to access files or directories.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP Cloud Connector | =2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-33692 is classified as a high severity vulnerability with potential for unauthorized file access.
To mitigate CVE-2021-33692, update SAP Cloud Connector to the latest version that addresses this vulnerability.
CVE-2021-33692 allows attackers to exploit file path traversal to access sensitive files or directories.
Yes, CVE-2021-33692 can be exploited remotely if the SAP Cloud Connector is accessible over the network.
SAP Cloud Connector version 2.0 is specifically affected by CVE-2021-33692.