SAP Security Note
Medium priority
SAP security note 2091403, “Directory traversal in BC-MID-ICF”, is a note released on 14.07.2020. Below are the symptom and SAP recommended solution.
Description
Symptom
BC-MID-ICF fails to correctly validate the file paths used to reference files on the remote server. This allows attackers to manipulate the path and access arbitrary files within the system, potentially exposing sensitive data.
Solution
Apply the coding changes as per the correction instructions provided in the SAP Note or implement the appropriate Support Package for your SAP_BASIS version.
CVSS
Score 6.3 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Full note on SAP: SAP Support Launchpad note 2091403
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
