SAP Security Note
Medium priority
SAP security note 2971112, "[CVE-2020-26807] Incorrect Default Permissions in SAP ERP Client for E-Bilanz 1.0", is a program error note released on 10.11.2020. Below are the symptom and SAP recommended solution.
Description
Symptom
On installation of SAP ERP Client for E-Bilanz 1.0, incorrect default filesystem permissions are set in its installation folder which allows anyone to modify the files in the folder.
Solution
The issue has been fixed by removing default and unnecessary filesystem permissions from the installation folder after installation of SAP ERP client for E-Bilanz 1.0 Patch-Level 12.
The SAP ERP client for E-Bilanz 1.0 Patch-Level 12 can be downloaded in this link.
To know how to install or upgrade from existing SAP ERP client for E-Bilanz 1.0 installation, you can refer to this link.
Reason and prerequisites
The application is vulnerable if you are using either of the following patches of SAP ERP client for E-Bilanz 1.0:
- Patch-Level 09 (Build 1.0.3.52)
- Patch-Level 10 (Build 1.0.3.53)
- Patch-Level 11 (Build 1.0.3.54)
CVSS
Score 4.4 Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Full note on SAP: SAP Support Launchpad note 2971112
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
