CVE-2023-49058: SAP Master Data Governance
Medium severity, CVSS 5.3. EPSS: 0.6% chance of exploitation in the next 30 days.
SAP Master Data Governance File Upload application allows an attacker to exploit insufficient validation of path information provided by users, thus characters representing ‘traverse to parent directory’ are passed through to the file APIs. As a result, it has a low impact to the confidentiality.
Affected products
- SAP Master Data Governance: version 731 only; version 732 only; version 746 only; version 747 only; version 748 only; version 749 only; …
Published 2023-12-12. Last modified 2026-06-17.