Overview
- Description
- SAP CRM, 7.01, 7.02,7.30, 7.31, 7.33, 7.54, allows an attacker to exploit insufficient validation of path information provided by users, thus characters representing "traverse to parent directory" are passed through to the file APIs.
- Source
- cna@sap.com
- NVD status
- Modified
Risk scores
CVSS 3.0
- Type
- Primary
- Base score
- 6.6
- Impact score
- 3.7
- Exploitability score
- 2.3
- Vector string
- CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L
- Severity
- MEDIUM
CVSS 2.0
- Type
- Primary
- Base score
- 6.5
- Impact score
- 6.4
- Exploitability score
- 8
- Vector string
- AV:N/AC:L/Au:S/C:P/I:P/A:P
Known exploits
Data from CISA
- Vulnerability name
- SAP Customer Relationship Management (CRM) Path Traversal Vulnerability
- Exploit added on
- Nov 3, 2021
- Exploit action due
- May 3, 2022
- Required action
- Apply updates per vendor instructions.
Weaknesses
- nvd@nist.gov
- CWE-22
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:sap:customer_relationship_management:7.01:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "136E88EF-877A-4881-B098-3472E02FC45A" }, { "criteria": "cpe:2.3:a:sap:customer_relationship_management:7.02:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3029F4DC-63CD-49C6-A98E-5A5B01E104FA" }, { "criteria": "cpe:2.3:a:sap:customer_relationship_management:7.30:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "51E097C6-61E3-4D8A-ABEC-A32BA68E3D87" }, { "criteria": "cpe:2.3:a:sap:customer_relationship_management:7.31:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4258AAE6-ABD0-47C1-B794-E68D3A57EEE0" }, { "criteria": "cpe:2.3:a:sap:customer_relationship_management:7.33:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4392BD0F-A286-4AEA-89E5-D151034C9055" }, { "criteria": "cpe:2.3:a:sap:customer_relationship_management:7.54:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CFD82446-BD1D-40E7-A216-2239B7D07691" } ], "operator": "OR" } ] } ]