SAP security note 1503974, "Directory Traversal in BC-MOB-LAP". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
BC-MOB-LAP contains a vulnerability that allows a malicious user to potentially read and write arbitrary files on the client. This can lead to client corruption, unauthorized access to confidential information, and alteration of the NetWeaver Mobile client’s behavior.
Solution
To address this security vulnerability, the JSP application is now launched from within the client status monitor, which operates with the permissions of the logged-in user rather than administrative rights.
Reason and prerequisites
When the NetWeaver Mobile laptop client is launched as a Windows service, it operates with administrator rights. If a JSP application is launched within a browser from this laptop client, the application inherits these administrator rights. A malicious user can exploit this by traversing the directory structure of the client to read sensitive files or write to restricted directories, potentially corrupting the system or altering the client’s behavior.
Affected components
- NWMCLIENTSETUP: Versions 7.10 to 7.11
Full note on SAP: SAP Support Launchpad note 1503974
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
