cbcvebase.

Sap Se Sapcar vulnerabilities

5 known vulnerabilities affecting sap_se/sapcar.

Total CVEs
5
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1MEDIUM4

Vulnerabilities

Page 1 of 1
CVE-2022-26100P3CRITICALCVSS 9.8fixed in 7.222022-03-10
CVE-2022-26100 [CRITICAL] CWE-129 CVE-2022-26100: SAPCAR - version 7.22, does not contain sufficient input validation on the SAPCAR archive. As a resu SAPCAR - version 7.22, does not contain sufficient input validation on the SAPCAR archive. As a result, the SAPCAR process may crash, and the attacker may obtain privileged access to the system.
nvd
CVE-2025-42970P4MEDIUMCVSS 5.8vSAP_CAR 7.53v7.22EXT2025-07-08
CVE-2025-42970 [MEDIUM] CWE-22 CVE-2025-42970: SAPCAR improperly sanitizes the file paths while extracting SAPCAR archives. Due to this, an attacke SAPCAR improperly sanitizes the file paths while extracting SAPCAR archives. Due to this, an attacker could craft a malicious SAPCAR archive containing directory traversal sequences. When a high privileged victim extracts this malicious archive, it is then processed by SAPCAR on their system, causing files to be extracted outside the intended directo
nvd
CVE-2025-42992P4MEDIUMCVSS 6.9vSAP_CAR 7.53v7.22EXT2025-07-08
CVE-2025-42992 [MEDIUM] CWE-266 CVE-2025-42992: SAPCAR allows an attacker logged in with high privileges to create a malicious SAR archive in SAPCAR SAPCAR allows an attacker logged in with high privileges to create a malicious SAR archive in SAPCAR. This could enable the attacker to exploit critical files and directory permissions without breaking signature validation, resulting in potential privilege escalation. This has high impact on integrity, but low impact on confidentiality and availabil
nvd
CVE-2025-43001P4MEDIUMCVSS 6.9vSAP_CAR 7.53v7.22EXT2025-07-08
CVE-2025-43001 [MEDIUM] CWE-266 CVE-2025-43001: SAPCAR allows an attacker logged in with high privileges to override the permissions of the current SAPCAR allows an attacker logged in with high privileges to override the permissions of the current and parent directories of the user or process extracting the archive, leading to privilege escalation. On successful exploitation, an attacker could modify the critical files by tampering with signed archives without breaking the signature, but it has
nvd
CVE-2025-42971P4MEDIUMCVSS 4.0vSAP_CAR 7.53v7.22EXT2025-07-08
CVE-2025-42971 [MEDIUM] CWE-787 CVE-2025-42971: A memory corruption vulnerability exists in SAPCAR allowing an attacker to craft malicious SAPCAR ar A memory corruption vulnerability exists in SAPCAR allowing an attacker to craft malicious SAPCAR archives. When a high privileged victim extracts this malicious archive, it gets processed by SAPCAR on their system, resulting in out-of-bounds memory read and write. This could lead to file extraction and file overwrite outside the intended directorie
nvd
Sap Se Sapcar vulnerabilities | cvebase