Directory Traversal Vulnerability in SAP NetWeaver (BI CONT ADD ON) Versions 707, 737, 747, 757

Directory Traversal Vulnerability in SAP NetWeaver (BI CONT ADD ON) Versions 707, 737, 747, 757

CVE-2023-33989 · HIGH Severity

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

An attacker with non-administrative authorizations in SAP NetWeaver (BI CONT ADD ON) - versions 707, 737, 747, 757, can exploit a directory traversal flaw to over-write system files. Data from confidential files cannot be read but potentially some OS files can be over-written leading to system compromise.

Learn more about our Web Application Penetration Testing UK.