Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Potential uploading of malicious files in SLD, SAP security note 1810809

SAP Note 1810809

SAP security note 1810809, "Potential uploading of malicious files in SLD". Below are the symptom and SAP recommended solution.

Description

Symptom

An attacker can exploit the SLD file uploading functionality.

Solution

Update your AS Java to a Support Package (SP) or release where the issue is fixed. Refer to the Support Package Patch Level section below for details and available patches.

Reason and prerequisites

File uploading functionality exists in SLD. Due to a program error, an attacker can misuse it to upload malicious files to a specific server folder and subsequently use those files to further attack AS Java.

CVSS

Score 4.9 Vector: AV:N/AC:M/AU:S/C:N/I:P/A:P

Full note on SAP: SAP Support Launchpad note 1810809

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More