← back
CVE-2023-29186highCWE-22

Directory/Path Traversal vulnerability in SAP NetWeaver.

26Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 8.7epss 23%
exploitation probability
23%top 2% of all CVEs
observed exploitation
nono source reports it
In short

A flaw in SAP NetWeaver allows attackers with administrative access to bypass file upload restrictions and overwrite critical files on the server, potentially crashing the system. While attackers cannot read files through this vulnerability, they can damage or destroy important system files.

Technical detail

A directory traversal vulnerability in SAP NetWeaver BI CONT ADDON (versions 707, 737, 747, 757) permits authenticated attackers with elevated privileges to upload and overwrite arbitrary files via a report interface, bypassing path validation controls. The attack vector requires administrative credentials and can result in denial of service by corrupting critical OS files; confidentiality is not impacted as file read access is not possible.

Summary generated and translated by AI from the official description.
In SAP NetWeaver (BI CONT ADDON) - versions 707, 737, 747, 757, an attacker can exploit a directory traversal flaw in a report to upload and overwrite files on the SAP server. Data cannot be read but if a remote attacker has sufficient (administrative) privileges then potentially critical OS files can be overwritten making the system unavailable.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:H