Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2019-0259 Unrestricted File Upload vulnerability in BO 4.2/ Visual Difference, SAP security note 2727564

SAP Note 2727564

SAP security note 2727564, "[CVE-2019-0259] Unrestricted File Upload vulnerability in BO 4.2/ Visual Difference", is a note. Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

BO 4.2/ Visual Difference allows an attacker to upload any file (including script files) without proper file format validation.

Some well-known impacts of Unrestricted File Upload vulnerability are:

  • Malicious file insertion or modification
  • Make the Web site vulnerable to some other attacks such as XSS

Solution

We have restricted the file upload type to lcmbiar only. The existing functionalities are not impacted after implementing this security note.

This issue is fixed in the patches listed in the "Support Packages & Patches" section below. The "Support Packages & Patches" section will be populated with the relevant patch levels once they are released.

Reason and prerequisites

Visual Difference is used to compare the reference and the target info objects by uploading lcmbiar file. Currently, it does not check the type of file system when selecting it and hence it is vulnerable to upload any file type. However, the usage of the Visual Difference can be done only by logging into CMC tool with a user having enough access privileges.

CVSS

Score 6.3 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

References

  • CVE-2019-0259

Affected components

  • ENTERPRISE 420
  • ENTERPRISE 430

Full note on SAP: SAP Support Launchpad note 2727564

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More