First published: Tue Apr 12 2022(Updated: )
A highly privileged remote attacker, can gain unauthorized access to display contents of restricted directories by exploiting insufficient validation of path information in SAP Focused Run (Simple Diagnostics Agent 1.0) - version 1.0.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP Focused Run | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2022-27657.
The severity of CVE-2022-27657 is medium with a severity value of 2.7.
The affected software in CVE-2022-27657 is SAP Focused Run (Simple Diagnostics Agent 1.0) - version 1.0.
An attacker can exploit CVE-2022-27657 by gaining unauthorized access to display contents of restricted directories through insufficient validation of path information.
Yes, there are references for CVE-2022-27657. You can find them at the following links: [link1](http://packetstormsecurity.com/files/167563/SAP-FRUN-Simple-Diagnostics-Agent-1.0-Directory-Traversal.html), [link2](http://seclists.org/fulldisclosure/2022/Jun/41), [link3](https://launchpad.support.sap.com/#/notes/3159091).