Description
SAP Portal fails to correctly validate the path with which a file that is read from the remote server is referenced. Through this, an attacker can potentially point the program to an arbitrary other file on the system, disclosing its contents.
Remediation
Install SAP security note 1630293.
References
Related Vulnerabilities
WordPress Plugin OPS Old Post Spinner 'ops_file' Parameter Local File Include (2.2.1)
PaperCut NG/MF Path Traversal (CVE-2023-39143)
WordPress Plugin Import and export users and customers Directory Traversal (1.14.2)
WordPress Plugin MasterStudy LMS-for Online Courses and Education Local File Inclusion (3.3.3)