Description
An attacker with non-administrative authorizations in SAP NetWeaver (BI CONT ADD ON) - versions 707, 737, 747, 757, can exploit a directory traversal flaw to over-write system files. Data from confidential files cannot be read but potentially some OS files can be over-written leading to system compromise.
References (2)
Core 2
Core References
Permissions Required
https://me.sap.com/notes/3331376
Scores
CVSS v3
8.7
EPSS
0.0026
EPSS Percentile
49.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-22
Status
published
Products (4)
sap/netweaver_bi_content
707
sap/netweaver_bi_content
737
sap/netweaver_bi_content
747
sap/netweaver_bi_content
757
Published
Jul 11, 2023
Tracked Since
Feb 18, 2026