Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Directory traversal in BC-WD-JAV, SAP security note 1852847

SAP Note 1852847

SAP security note 1852847, “Directory traversal in BC-WD-JAV”, is a note. Below is the security information published by SAP for this note.

Description

Symptom: BC-WD-JAV contains a vulnerability that allows an attacker to potentially read arbitrary files on the remote server, which may lead to the disclosure of confidential information.

CVSS Information:

  • CVSS Base Score: 5.0
  • CVSS Base Vector: AV:N/AC:L/AU:N/C:P/I:N/A:N

*Note:* The CVSS score provided by SAP estimates the risk posed by the issue and does not account for your specific system configuration or operational environment. It's recommended to conduct your own risk assessment when determining the applicability or priority of this security note. For more details, refer to the SAP Security Notes FAQ.

Reason and Prerequisites: BC-WD-JAV fails to correctly validate the path used to reference a file that is read from the remote server. This flaw allows an attacker to direct the program to an arbitrary file in the system, potentially disclosing its contents.

Solution: Apply the SAP Security Note 1852847 to address and fix the reported issue.

Affected components

  • WD-RUNTIME 7.20
  • WD-RUNTIME 7.30
  • WD-RUNTIME 7.31
  • WD-RUNTIME 7.40

Full note on SAP: SAP Support Launchpad note 1852847

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More