Description
A security vulnerability exists in SAP B2B/B2C CRM that allows an attacker to read arbitrary local files from the affected server. The file initProductCatalog.do is affected and this vulnerability can be exploited via the GET parameter forwardPath.
Remediation
Upgrade SAP B2B/B2C CRM to the latest version.
Please consult the SAP Security Note 1870255656 for more information about the fix.
References
Related Vulnerabilities
WordPress Plugin Ninja Forms with File Uploads Extension Multiple Vulnerabilities (3.0.22)
Local File Inclusion (CMS Made Simple)
WordPress Plugin MasterStudy LMS-for Online Courses and Education Local File Inclusion (3.3.0)
PaperCut NG/MF Path Traversal (CVE-2023-39143)
WordPress Plugin JetWidgets for Elementor and WooCommerce Local File Inclusion (1.1.7)