SAP Business Connector Remote Arbitrary File Access And Deletion Vulnerability
BID:16668
Info
SAP Business Connector Remote Arbitrary File Access And Deletion Vulnerability
| Bugtraq ID: | 16668 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 15 2006 12:00AM |
| Updated: | May 16 2006 08:54PM |
| Credit: | Leandro Meiners of CYBSEC S.A. Security Systems discovered this vulnerability. |
| Vulnerable: |
SAP Business Connector 4.7 SAP Business Connector 4.6 |
| Not Vulnerable: | |
Discussion
SAP Business Connector Remote Arbitrary File Access And Deletion Vulnerability
SAP Business Connector is prone to a file-access/deletion vulnerability. This issue arises due to an access-validation error.
A successful attack will result in the disclosure of sensitive or privileged information. An attacker may also delete arbitrary files. This often occurs with superuser privileges, since the package is often run with elevated privileges to gain access to TCP ports lower than 1024.
SAP Business Connector is prone to a file-access/deletion vulnerability. This issue arises due to an access-validation error.
A successful attack will result in the disclosure of sensitive or privileged information. An attacker may also delete arbitrary files. This often occurs with superuser privileges, since the package is often run with elevated privileges to gain access to TCP ports lower than 1024.
Exploit / POC
SAP Business Connector Remote Arbitrary File Access And Deletion Vulnerability
This issue can be exploited with a web client.
Proof-of-concept examples are available:
This issue can be exploited with a web client.
Proof-of-concept examples are available:
Solution / Fix
SAP Business Connector Remote Arbitrary File Access And Deletion Vulnerability
Solution:
The vendor has reportedly released fixes addressing this issue. Users of affected packages should contact the vendor for further information on obtaining fixes.
Solution:
The vendor has reportedly released fixes addressing this issue. Users of affected packages should contact the vendor for further information on obtaining fixes.
References
SAP Business Connector Remote Arbitrary File Access And Deletion Vulnerability
References:
References: