Description
SAP Enterprise Architecture Designer v1.0 SP04 allows an authenticated attacker to exploit insufficient validation of path information provided by users, thus characters representing ‘traverse to parent directory’ are passed through to the file APIs.
This could be achieved by injecting malicious crafted Zip file (“Zip Slip” CVE-2018-1002204).
Some well-known impacts of Directory Traversal vulnerability are –
- attacker could overwrite, delete, or corrupt arbitrary files on the remote server
Available fix and Supported packages
- XSAC_HANA_EA_D | 1 | 1
- SAP EA DESIGN FOR SAP HANA 1.0 | SP004 | 000003
Affected component
- BC-EAD
SAP Enterprise Architecture Designer
CVSS
Score: 5.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N
PoC
Detailed vulnerability information added to RedRays Security Platform. Contact [email protected] for details.
URL
https://launchpad.support.sap.com/#/notes/2709897