CVE-2022-27657

LOW

SAP Focused Run Simple Diagnostics Agent 1.0 - Path Traversal

Title source: llm
STIX 2.1

Description

A highly privileged remote attacker, can gain unauthorized access to display contents of restricted directories by exploiting insufficient validation of path information in SAP Focused Run (Simple Diagnostics Agent 1.0) - version 1.0.

References (4)

Core 4
Core References
Permissions Required, Vendor Advisory x_refsource_misc
https://launchpad.support.sap.com/#/notes/3159091
Mailing List, Third Party Advisory mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2022/Jun/41

Scores

CVSS v3 2.7
EPSS 0.0029
EPSS Percentile 52.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-22
Status published
Products (1)
sap/focused_run 1.0
Published Apr 12, 2022
Tracked Since Feb 18, 2026