SAP security note 1466529, "Directory Traversel in BW OLAP RFC", is a program error note released on 14.12.2010. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
BW has an RFC without further authority checks, which contains a vulnerability that allows a malicious user to potentially write arbitrary files on the remote server, possibly corrupting data or altering system behavior.
Solution
- The corresponding code is not actively used and has been removed.
- Apply the corresponding note or Support Package.
Reason and prerequisites
The RFC fails to correctly validate the path where a user-submitted file is written. This allows an attacker to potentially overwrite data on the remote system.
Affected components
- SAP_BW: Versions 30B, 310, 350, 700 to 702, 711
- SAP_BW_VIRTUAL_COMP: Version 30B
Full note on SAP: SAP Support Launchpad note 1466529
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
