Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2018-2467 File Path Disclosure in SAP Business Intelligence Software Development Kit, SAP security note 2623618

SAP Note 2623618
Medium priority

SAP security note 2623618, "[CVE-2018-2467] File Path Disclosure in SAP Business Intelligence Software Development Kit", was released on October 9, 2018. Below are the symptom, SAP recommended solution and the affected software components.

PriorityMedium priority
StatusReleased for Customer
Released onOctober 9, 2018

Description

Symptom

A vulnerability was identified in SAP BusinessObjects BI Platform Servers (versions 4.1 and 4.2) where using a specially crafted URL in a web browser such as Chrome could cause the system to return an error displaying the file path of the application server. This information disclosure can lead to:

  • Loss of information and system configuration confidentiality
  • Information gathering for further exploits and attacks

Solution

The issue has been addressed by SAP by handling the error within the application and providing a standard error message to users. This fix is available in the relevant support packages.

CVSS

Score 5.3/10 Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Affected components

  • SAP BusinessObjects BI Platform Servers (4.1 and 4.2)

Full note on SAP: SAP Support Launchpad note 2623618

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More