Skip links
Arpine Maghakyan

Arpine Maghakyan

Security Researcher of RedRays.

CVE-2020-26807 Incorrect Default Permissions in SAP ERP Client for E-Bilanz 1.0, SAP security note 2971112

Description

On installation of SAP ERP Client for E-Bilanz 1.0, Incorrect default filesystem permissions are set in its installation folder which allows anyone to modify the files in the folder.

Available fix and Supported packages

  • EBILANZ | 100 | 100
  • E-BILANZ CLIENT 1.0 | SP003 | 000012

Affected component

    EPM-EBI
    SAP ERP Client For E-Bilanz

CVSS

Score: 4.4
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L

Exploit

Detailed vulnerability information added to RedRays Security Platform. Contact [email protected] for details.

URL

https://launchpad.support.sap.com/#/notes/2971112

TAGS

#Access-rights
#Access-control
#ACL
#Filesystem-permissions
#&160-CVE-2020-26807

More to explorer

SAP Cloud Connector Certificate Validation Issue

Date of Release: February 13, 2024 Advisory ID: CVE-2024-25642 Affected Software: SAP Cloud Connector Versions Affected: 2.15.0 to 2.16.1 Vulnerability Summary:A critical vulnerability,