SAP Security Note
High priority
SAP security note 2067830, “Security issue with AV protection in webdynpro file upload”, is a program error note released on 14.04.2015. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
BC-WD-JAV has a vulnerability that allows a malicious file to be uploaded to a system when a virus scanner is not configured correctly.
Solution
Apply SAP Note 2067830 to receive the necessary fix.
- Verify Configuration: Ensure that the virus scanner is correctly configured to validate all uploaded files.
- Apply the Note: Follow the solution provided in SAP Note 2067830 to implement the necessary fixes.
- Update Support Packages: Install the relevant support package patches for your WebDynpro Java runtime version.
Reason and prerequisites
BC-WD-JAV fails to validate malicious files during file upload when using a misconfigured scanner.
CVSS
Score 5.8 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:P
References
Affected components
- WEB DYNPRO RUNTIME 7.11 to 7.40
Full note on SAP: SAP Support Launchpad note 2067830
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




