SAP Master Data Management におけるパストラバーサルの脆弱性
| Title |
SAP Master Data Management におけるパストラバーサルの脆弱性
|
| Summary |
SAP Master Data Management には、パストラバーサルの脆弱性が存在します。
|
| Possible impacts |
情報を取得される可能性があります。 |
| Solution |
ベンダより正式な対策が公開されています。ベンダ情報を参照して適切な対策を実施してください。 |
| Publication Date |
Feb. 9, 2021, midnight |
| Registration Date |
Nov. 1, 2021, 2:22 p.m. |
| Last Update |
Nov. 1, 2021, 2:22 p.m. |
|
CVSS3.0 : 重要
|
| Score |
7.5
|
| Vector |
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
|
CVSS2.0 : 警告
|
| Score |
5
|
| Vector |
AV:N/AC:L/Au:N/C:P/I:N/A:N |
Affected System
| SAP |
|
NetWeaver Master Data Management Server 710
|
|
NetWeaver Master Data Management Server 710.750
|
CVE (情報セキュリティ 共通脆弱性識別子)
CWE (共通脆弱性タイプ一覧)
ベンダー情報
Change Log
| No |
Changed Details |
Date of change |
| 1 |
[2021年11月01日] 掲載 |
Nov. 1, 2021, 2:22 p.m. |
NVD Vulnerability Information
CVE-2021-21475
| Summary |
Under specific circumstances SAP Master Data Management, versions - 710, 710.750, allows an unauthorized attacker to exploit insufficient validation of path information provided by users, thus characters representing 'traverse to parent directory' are passed through to the file APIs. Due to this Directory Traversal vulnerability the attacker could read content of arbitrary files on the remote server and expose sensitive data.
|
| Publication Date |
Feb. 10, 2021, 6:15 a.m. |
| Registration Date |
Feb. 10, 2021, 9:42 a.m. |
| Last Update |
Nov. 21, 2024, 2:48 p.m. |
Affected software configurations
| Configuration1 |
or higher |
or less |
more than |
less than |
| cpe:2.3:a:sap:netweaver_master_data_management_server:710.750:*:*:*:*:*:*:* |
|
|
|
|
| cpe:2.3:a:sap:netweaver_master_data_management_server:710:*:*:*:*:*:*:* |
|
|
|
|
Related information, measures and tools
Common Vulnerabilities List