Loading HuntDB...

GHSA-4f5h-cfp2-m9r7

GitHub Security Advisory

⚠ Unreviewed MODERATE Has CVE

Advisory Details

SAP Note Assistant tool (SAP BASIS from 7.00 to 7.02, from 7.10 to 7.11, 7.30, 7.31,7.40, from 7.50 to 7.52) supports upload of digitally signed note file of type 'SAR'. The digital signature verification is done together with the extraction of note file contained in the SAR archive. It is possible to append a tampered file to the SAR archive using SAPCAR tool and during the extraction, digital signature verification fails but the tampered file is extracted.

Related CVEs

Key Information

GHSA ID
GHSA-4f5h-cfp2-m9r7
Published
May 14, 2022 4:00 AM
Last Modified
April 20, 2025 3:49 AM
CVSS Score
5.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: June 18, 2025 6:25 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.