Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Directory traversal in GW, SAP security note 2074736

SAP Note 2074736

SAP security note 2074736, "Directory Traversal Vulnerability in SAP Gateway (GW)", is a note. Below are the symptom, SAP recommended solution and the affected software components.

ComponentBC-CST-GW (Basis Components > Client/Server Technology > Gateway/CPIC)

Description

Symptom

SAP Security Note 2074736 addresses a critical directory traversal vulnerability in the SAP Gateway (GW). This vulnerability allows an attacker to write arbitrary files to the remote server, potentially leading to data corruption or unauthorized alterations to system behavior.

Solution

A new instance profile parameter has been introduced to mitigate this vulnerability. The fix is available through support package patches for the affected SAP Kernel releases. For detailed instructions and patches, refer to SAP Note 2035100.

Reason and prerequisites

The SAP Gateway (GW) fails to properly validate the file path provided by users. This oversight allows attackers to overwrite data on the remote server, leading to potential system corruption or altered functionalities.

CVSS

Score 6.0 Vector: AV:N/AC:M/AU:S/C:P/I:P/A:P

References

Affected components

  • BC-CST-GW (Basis Components > Client/Server Technology > Gateway/CPIC)
  • Kernel Versions: 7.20, 7.21, 7.40, 7.41, 7.42 (both 32-bit and 64-bit, with and without Unicode)

Full note on SAP: SAP Support Launchpad note 2074736

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More