SAP NetWeaver Directory Traversal Vulnerability
BID:62391
Info
SAP NetWeaver Directory Traversal Vulnerability
| Bugtraq ID: | 62391 |
| Class: | Input Validation Error |
| CVE: |
CVE-2013-5751 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 13 2013 12:00AM |
| Updated: | Apr 13 2015 09:01PM |
| Credit: | Pavel Toporkov of Positive Technologies |
| Vulnerable: |
SAP NetWeaver 7.30 SP04 SAP NetWeaver 7.30 SAP NetWeaver 7.10 SAP NetWeaver 7.03 SAP NetWeaver 7.02 SP06 SAP NetWeaver 7.02 SAP NetWeaver 7.01 SR1 SAP NetWeaver 7.01 SAP NetWeaver 7.0 SP8 SAP NetWeaver 7.0 SP15 SAP NetWeaver 7.0 EHP2 SAP NetWeaver 7.0 EHP1 SAP NetWeaver 7.0 |
| Not Vulnerable: | |
Discussion
SAP NetWeaver Directory Traversal Vulnerability
SAP NetWeaver is prone to a directory-traversal vulnerability because it fails to properly sanitize user-supplied input.
Remote attackers can use specially crafted requests with directory-traversal sequences ('../') to retrieve arbitrary files in the context of the application. This may aid in further attacks.
SAP NetWeaver is prone to a directory-traversal vulnerability because it fails to properly sanitize user-supplied input.
Remote attackers can use specially crafted requests with directory-traversal sequences ('../') to retrieve arbitrary files in the context of the application. This may aid in further attacks.
Exploit / POC
SAP NetWeaver Directory Traversal Vulnerability
An attacker can exploit the issue through a browser.
An attacker can exploit the issue through a browser.
References
SAP NetWeaver Directory Traversal Vulnerability
References:
References: