CVE-2023-27500: SAP NetWeaver Application Server Abap

High severity, CVSS 8.1. EPSS: 1% chance of exploitation in the next 30 days.

An attacker with non-administrative authorizations can exploit a directory traversal flaw in program SAPRSBRO to over-write system files. In this attack, no data can be read but potentially critical OS files can be over-written making the system unavailable.

Affected products

  • SAP NetWeaver Application Server Abap: version 700 only; version 701 only; version 702 only; version 731 only; version 740 only; version 750 only; …

Published 2023-03-14. Last modified 2026-06-17.