CVE-2023-29186: Directory/Path Traversal vulnerability in SAP NetWeaver.
In SAP NetWeaver (BI CONT ADDON) - versions 707, 737, 747, 757, an attacker can exploit a directory traversal flaw in a report to upload and overwrite files on the SAP server. Data cannot be read but if a remote attacker has sufficient (administrative) privileges then potentially critical OS files can be overwritten making the system unavailable.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-29186?
The severity of CVE-2023-29186 is high.
Which versions of SAP NetWeaver (BI CONT ADDON) are affected by CVE-2023-29186?
Versions 707, 737, 747, and 757 of SAP NetWeaver (BI CONT ADDON) are affected by CVE-2023-29186.
How can an attacker exploit CVE-2023-29186?
An attacker can exploit CVE-2023-29186 by exploiting a directory traversal flaw in a report to upload and overwrite files on the SAP server.
Can an attacker read data through CVE-2023-29186?
No, data cannot be read through CVE-2023-29186, but a remote attacker with sufficient privileges can potentially overwrite critical OS files.
Are there any security notes or references related to CVE-2023-29186?
Yes, you can refer to the following security notes for more information on CVE-2023-29186: [Link 1](https://launchpad.support.sap.com/#/notes/3305907) and [Link 2](https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html).