SAP security note 2727564, "[CVE-2019-0259] Unrestricted File Upload vulnerability in BO 4.2/ Visual Difference", is a note. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
BO 4.2/ Visual Difference allows an attacker to upload any file (including script files) without proper file format validation.
Some well-known impacts of Unrestricted File Upload vulnerability are:
- Malicious file insertion or modification
- Make the Web site vulnerable to some other attacks such as XSS
Solution
We have restricted the file upload type to lcmbiar only. The existing functionalities are not impacted after implementing this security note.
This issue is fixed in the patches listed in the "Support Packages & Patches" section below. The "Support Packages & Patches" section will be populated with the relevant patch levels once they are released.
Reason and prerequisites
Visual Difference is used to compare the reference and the target info objects by uploading lcmbiar file. Currently, it does not check the type of file system when selecting it and hence it is vulnerable to upload any file type. However, the usage of the Visual Difference can be done only by logging into CMC tool with a user having enough access privileges.
CVSS
Score 6.3 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
References
- CVE-2019-0259
Affected components
- ENTERPRISE 420
- ENTERPRISE 430
Full note on SAP: SAP Support Launchpad note 2727564
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
