Aller au contenu

Fiche vulnérabilité

CVE-2021-21475 : faille élevée sap netweaver master data management… (CVSS 7.5)

Description

Under specific circumstances SAP Master Data Management, versions - 710, 710.750, allows an unauthorized attacker to exploit insufficient validation of path information provided by users, thus characters representing 'traverse to parent directory' are passed through to the file APIs. Due to this Directory Traversal vulnerability the attacker could read content of arbitrary files on the remote server and expose sensitive data.

En bref

Sévérité
Élevée (CVSS 7.5)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitation active
Non signalée par la CISA
Publication
9 févr. 2021
Dernière mise à jour
17 juin 2026

Produits concernés

  • sap netweaver master data management server

Références

Rechercher une autre vulnérabilité dans la base CVE