SAP security note 1810809, "Potential uploading of malicious files in SLD". Below are the symptom and SAP recommended solution.
Description
Symptom
An attacker can exploit the SLD file uploading functionality.
Solution
Update your AS Java to a Support Package (SP) or release where the issue is fixed. Refer to the Support Package Patch Level section below for details and available patches.
Reason and prerequisites
File uploading functionality exists in SLD. Due to a program error, an attacker can misuse it to upload malicious files to a specific server folder and subsequently use those files to further attack AS Java.
CVSS
Score 4.9 Vector: AV:N/AC:M/AU:S/C:N/I:P/A:P
Full note on SAP: SAP Support Launchpad note 1810809
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
