PT-2017-3748 · Sap · Sap Business Process Automation (Bpa) By Redwood

Aleksandr Shvetsov

+2

·

Publicado

2017-03-16

·

Atualizado

2019-10-09

·

CVE-2018-2366

CVSS v3.1

4.3

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions: SAP Business Process Automation (BPA) By Redwood versions 9.0 through 9.1
Description: The issue is related to insufficient validation of path information provided by users, allowing an attacker to exploit this weakness. This can lead to the traversal of directory paths, potentially enabling the attacker to access arbitrary files on the server, including system files, and obtain critical information by escaping the intended directory boundaries.
Recommendations: For versions 9.0 and 9.1, consider restricting access to file APIs to minimize the risk of exploitation until a patch is available. As a temporary workaround, limit the ability of users to provide path information to prevent directory traversal attacks.

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2019-00301
CVE-2018-2366

Produtos afetados

Sap Business Process Automation (Bpa) By Redwood