Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Directory traversal in BC-MID-ICF, SAP security note 2091403

SAP Note 2091403
SAP Security Note
Medium priority

SAP security note 2091403, “Directory traversal in BC-MID-ICF”, is a note released on 14.07.2020. Below are the symptom and SAP recommended solution.

ComponentBC-MID-ICF (Basis Components > Middleware > Internet Communication Framework)
PriorityMedium priority
TypeSAP Security Note
StatusReleased for Customer
Released on14.07.2020

Description

Symptom

BC-MID-ICF fails to correctly validate the file paths used to reference files on the remote server. This allows attackers to manipulate the path and access arbitrary files within the system, potentially exposing sensitive data.

Solution

Apply the coding changes as per the correction instructions provided in the SAP Note or implement the appropriate Support Package for your SAP_BASIS version.

CVSS

Score 6.3 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

Full note on SAP: SAP Support Launchpad note 2091403

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More