Vulnerability CVE-2024-27901


Published: 2024-04-09

Description:
SAP Asset Accounting could allow a high privileged attacker to exploit insufficient validation of path information provided by the users and pass it through to the file API's. Thus, causing a considerable impact on confidentiality, integrity and availability of the application.

Type:

CWE-35

(Path Traversal: '.../...//')

 References:
https://me.sap.com/notes/3438234
https://support.sap.com/en/my-support/knowledge-base/security-notes-news.html?anchorId=section_370125364

Copyright 2026, cxsecurity.com

 

Back to Top