Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2020-26807 Incorrect Default Permissions in SAP ERP Client for E-Bilanz 1.0, SAP security note 2971112

SAP Note 2971112
SAP Security Note
Medium priority

SAP security note 2971112, "[CVE-2020-26807] Incorrect Default Permissions in SAP ERP Client for E-Bilanz 1.0", is a program error note released on 10.11.2020. Below are the symptom and SAP recommended solution.

ComponentEnterprise Performance Management > SAP ERP Client For E-Bilanz
CategoryProgram error
PriorityCorrection with medium priority
TypeSAP Security Note
Version9
StatusReleased for Customer
Released on10.11.2020
LanguageEnglish

Description

Symptom

On installation of SAP ERP Client for E-Bilanz 1.0, incorrect default filesystem permissions are set in its installation folder which allows anyone to modify the files in the folder.

Solution

The issue has been fixed by removing default and unnecessary filesystem permissions from the installation folder after installation of SAP ERP client for E-Bilanz 1.0 Patch-Level 12.

The SAP ERP client for E-Bilanz 1.0 Patch-Level 12 can be downloaded in this link.

To know how to install or upgrade from existing SAP ERP client for E-Bilanz 1.0 installation, you can refer to this link.

Reason and prerequisites

The application is vulnerable if you are using either of the following patches of SAP ERP client for E-Bilanz 1.0:

  • Patch-Level 09 (Build 1.0.3.52)
  • Patch-Level 10 (Build 1.0.3.53)
  • Patch-Level 11 (Build 1.0.3.54)

CVSS

Score 4.4 Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L

Full note on SAP: SAP Support Launchpad note 2971112

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More