Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unrestricted File Upload vulnerability in SAP Gateway, SAP security note 2641674

SAP Note 2641674
SAP Security Note
Medium priority

SAP security note 2641674, "Unrestricted File Upload Vulnerability in SAP Gateway", was released on 25.07.2018. Below are the symptom, SAP recommended solution and the affected software components.

ComponentOccasional Platform User > Gateway > Framework (OPU-GW-COR)
PriorityCorrection with medium priority
TypeSAP Security Note
Version6
StatusReleased for Customer
Released on25.07.2018

Description

Symptom

SAP Gateway allows an attacker to upload any file (including script files) without proper file format validation.

Impacts of the unrestricted file upload vulnerability:

  • Malicious file insertion or modification
  • Makes the web site vulnerable to other attacks such as Cross-Site Scripting (XSS)

Solution

The virus scanning functionality is extended by this correction.

Please apply the Support Package of this SAP Note or follow the correction instructions to address the vulnerability.

Reason and prerequisites

Virus scanning may not be triggered in OData V2 for the navigation properties while using a deep create.

References

Affected components

  • SAP_GWFND: Versions 750, 751, 752, 753
  • SAP_BASIS: Version 773

Full note on SAP: SAP Support Launchpad note 2641674

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More