CVE-2023-27500: Directory Traversal vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform
An attacker with non-administrative authorizations can exploit a directory traversal flaw in program SAPRSBRO to over-write system files. In this attack, no data can be read but potentially critical OS files can be over-written making the system unavailable.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2023-27500.
What is the severity of CVE-2023-27500?
CVE-2023-27500 has a severity of 8.1 (critical).
How does the attacker exploit CVE-2023-27500?
The attacker exploits a directory traversal flaw in program SAPRSBRO to over-write system files.
What is the impact of CVE-2023-27500?
In this attack, no data can be read but potentially critical OS files can be over-written making the system unavailable.
Which software versions are affected by CVE-2023-27500?
SAP NetWeaver Application Server ABAP versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, and 757 are affected.
How can I fix CVE-2023-27500?
Please refer to the SAP security note for instructions on how to fix CVE-2023-27500: [link to SAP security note].
Where can I find more information about CVE-2023-27500?
You can find more information about CVE-2023-27500 in the following references: [link to SAP support note] [link to SAP document].