SAP ABAP File Interface CVE-2018-2367 Directory Traversal Vulnerability
BID:103006
CVE-2018-2367 |Info
SAP ABAP File Interface CVE-2018-2367 Directory Traversal Vulnerability
| Bugtraq ID: | 103006 |
| Class: | Input Validation Error |
| CVE: |
CVE-2018-2367 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 13 2018 12:00AM |
| Updated: | Feb 13 2018 12:00AM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
SAP Basis 7.52 SAP Basis 7.51 SAP Basis 7.50 SAP Basis 7.40 SAP Basis 7.31 SAP Basis 7.30 SAP Basis 7.11 SAP Basis 7.10 SAP Basis 7.02 SAP Basis 7.01 SAP Basis 7.00 |
| Not Vulnerable: | |
Discussion
SAP ABAP File Interface CVE-2018-2367 Directory Traversal Vulnerability
SAP ABAP File Interface is prone to a directory-traversal vulnerability because it fails to properly sanitize user-supplied input.
Remote attackers can use specially crafted requests with directory-traversal sequences ('../') to retrieve arbitrary files in the context of the application. This may aid in further attacks.
SAP BASIS 7.00 through 7.02, 7.10 through 7.11, 7.30, 7.31, 7.40, and 7.50 through 7.52 are vulnerable.
SAP ABAP File Interface is prone to a directory-traversal vulnerability because it fails to properly sanitize user-supplied input.
Remote attackers can use specially crafted requests with directory-traversal sequences ('../') to retrieve arbitrary files in the context of the application. This may aid in further attacks.
SAP BASIS 7.00 through 7.02, 7.10 through 7.11, 7.30, 7.31, 7.40, and 7.50 through 7.52 are vulnerable.
Solution / Fix
SAP ABAP File Interface CVE-2018-2367 Directory Traversal Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.