Description
In SAP NetWeaver (BI CONT ADDON) - versions 707, 737, 747, 757, an attacker can exploit a directory traversal flaw in a report to upload and overwrite files on the SAP server. Data cannot be read but if a remote attacker has sufficient (administrative) privileges then potentially critical OS files can be overwritten making the system unavailable.
References (2)
Core 2
Core References
Permissions Required
https://launchpad.support.sap.com/#/notes/3305907
Scores
CVSS v3
8.7
EPSS
0.0075
EPSS Percentile
73.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-22
Status
published
Products (4)
sap/netweaver
707
sap/netweaver
737
sap/netweaver
747
sap/netweaver
757
Published
Apr 11, 2023
Tracked Since
Feb 18, 2026