CVE-2021-44232 Information
Jun 07, 2022
cve
Description
SAF-T Framework Transaction SAFTN_G allows an attacker to exploit insufficient validation of path information provided by normal user leading to full server directory access. The attacker can see the whole filesystem structure but cannot overwrite delete or corrupt arbitrary files on the server.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Reference
https://launchpad.support.sap.com/#/notes/3124094 https://wiki.scn.sap.com/wiki/display/PSR/SAP+Security+Patch+Day+-+December+2021
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
CHANGED
Integrity Impact
HIGH
Availability Impact
NONE
Base Score
NONE
Base Severity
7.7
Share on: