SAP security note 865403, “IGS is vulnerable to directory traversal attacks via HTTP”. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
SAP Note 865403 addresses a vulnerability in the Internet Graphics Server (IGS) that allows directory traversal attacks via HTTP. An attacker can exploit this vulnerability to access files on the server with the same privileges as the user running the IGS.
Solution
SAP strongly recommends updating your SAP IGS installation to the following patch levels to mitigate this vulnerability:
- SAP IGS 6.40: Patchlevel 17
- SAPG IGS 7.00: Patchlevel 7
Additionally, consider the following alternatives to HTTP for monitoring the IGS:
- Use the report
GRAPHICS_IGS_ADMIN(see Note 995471) - Utilize CCMS (Computing Center Management System)
References
- IGS 7.00 Patch 7 (1002789)
- IGS 6.40 Patch 17 (997829)
- IGS administration via ABAP (995471)
- Enable tracing of IGS HTTP request (992171)
- IGS HTTP administration commands (965201)
- IGS HTTP administration is not possible (959358)
- Deactivating HTTP access to the IGS (862169)
Affected components
- Internet Graphics Server (IGS): Versions 6.40, 7.00
Full note on SAP: SAP Support Launchpad note 865403
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
