SAP security note 2074736, "Directory Traversal Vulnerability in SAP Gateway (GW)", is a note. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
SAP Security Note 2074736 addresses a critical directory traversal vulnerability in the SAP Gateway (GW). This vulnerability allows an attacker to write arbitrary files to the remote server, potentially leading to data corruption or unauthorized alterations to system behavior.
Solution
A new instance profile parameter has been introduced to mitigate this vulnerability. The fix is available through support package patches for the affected SAP Kernel releases. For detailed instructions and patches, refer to SAP Note 2035100.
Reason and prerequisites
The SAP Gateway (GW) fails to properly validate the file path provided by users. This oversight allows attackers to overwrite data on the remote server, leading to potential system corruption or altered functionalities.
CVSS
Score 6.0 Vector: AV:N/AC:M/AU:S/C:P/I:P/A:P
References
Affected components
- BC-CST-GW (Basis Components > Client/Server Technology > Gateway/CPIC)
- Kernel Versions: 7.20, 7.21, 7.40, 7.41, 7.42 (both 32-bit and 64-bit, with and without Unicode)
Full note on SAP: SAP Support Launchpad note 2074736
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
