CVE-2023-33989

CVSS 3.1 Score 8.1 of 10 (high)

Details

Published Jul 11, 2023
Updated: Jul 19, 2023
CWE ID 22

Summary

CVE-2023-33989 is a newly discovered vulnerability impacting the SAP NetWeaver Business Intelligence Cont Add-On in versions 707, 737, 747, and 757. This issue allows a non-administrative attacker to leverage a directory traversal flaw, enabling them to overwrite system files. Although data from confidential files cannot be directly read, some operating system files are at risk of being compromised, potentially leading to a system breach.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share