cbcvebase.
CVE-2023-33989
published 2023-07-11

CVE-2023-33989: An attacker with non-administrative authorizations in SAP NetWeaver (BI CONT ADD ON) - versions 707, 737, 747, 757, can exploit a directory traversal flaw to…

PriorityP348high8.1CVSS 3.1
AVNACLPRLUINSUCNIHAH
EPSS
0.97%
58.0th percentile
An attacker with non-administrative authorizations in SAP NetWeaver (BI CONT ADD ON) - versions 707, 737, 747, 757, can exploit a directory traversal flaw to over-write system files. Data from confidential files cannot be read but potentially some OS files can be over-written leading to system compromise.

Affected

8 ranges
VendorProductVersion rangeFixed in
sapnetweaver_bi_content
sapnetweaver_bi_content
sapnetweaver_bi_content
sapnetweaver_bi_content
sap_sesap_netweaver
sap_sesap_netweaver
sap_sesap_netweaver
sap_sesap_netweaver
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.