PT-2017-3748 · Sap · Sap Business Process Automation (Bpa) By Redwood

Aleksandr Shvetsov

+2

·

Published

2017-03-16

·

Updated

2019-10-09

·

CVE-2018-2366

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions: SAP Business Process Automation (BPA) By Redwood versions 9.0 through 9.1
Description: The issue is related to insufficient validation of path information provided by users, allowing an attacker to exploit this weakness. This can lead to the traversal of directory paths, potentially enabling the attacker to access arbitrary files on the server, including system files, and obtain critical information by escaping the intended directory boundaries.
Recommendations: For versions 9.0 and 9.1, consider restricting access to file APIs to minimize the risk of exploitation until a patch is available. As a temporary workaround, limit the ability of users to provide path information to prevent directory traversal attacks.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-00301
CVE-2018-2366

Affected Products

Sap Business Process Automation (Bpa) By Redwood