First published: Tue Mar 14 2023(Updated: )
An attacker with non-administrative authorizations can exploit a directory traversal flaw in program SAPRSBRO to over-write system files. In this attack, no data can be read but potentially critical OS files can be over-written making the system unavailable.
Credit: cna@sap.com cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP NetWeaver Application Server ABAP | =700 | |
SAP NetWeaver Application Server ABAP | =701 | |
SAP NetWeaver Application Server ABAP | =702 | |
SAP NetWeaver Application Server ABAP | =731 | |
SAP NetWeaver Application Server ABAP | =740 | |
SAP NetWeaver Application Server ABAP | =750 | |
SAP NetWeaver Application Server ABAP | =751 | |
SAP NetWeaver Application Server ABAP | =752 | |
SAP NetWeaver Application Server ABAP | =753 | |
SAP NetWeaver Application Server ABAP | =754 | |
SAP NetWeaver Application Server ABAP | =755 | |
SAP NetWeaver Application Server ABAP | =756 | |
SAP NetWeaver Application Server ABAP | =757 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2023-27500.
CVE-2023-27500 has a severity of 8.1 (critical).
The attacker exploits a directory traversal flaw in program SAPRSBRO to over-write system files.
In this attack, no data can be read but potentially critical OS files can be over-written making the system unavailable.
SAP NetWeaver Application Server ABAP versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, and 757 are affected.
Please refer to the SAP security note for instructions on how to fix CVE-2023-27500: [link to SAP security note].
You can find more information about CVE-2023-27500 in the following references: [link to SAP support note] [link to SAP document].