PT-2021-17553 · Sap · Sap Process Integration

Published

2021-05-11

·

Updated

2021-08-27

·

CVE-2021-27618

CVSS v3.1

4.9

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions SAP Process Integration versions 7.10 through 7.50
Description The issue concerns the Integration Builder Framework, which fails to check the file type extension of uploaded files from local sources. This oversight allows an attacker to craft and upload malicious files, potentially leading to denial of service and impacting the application's availability.
Recommendations For versions 7.10 through 7.50, consider implementing strict file type validation to prevent the upload of malicious files until a formal fix is available. As a temporary workaround, restrict access to file upload functionality to minimize the risk of exploitation.

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-27618

Affected Products

Sap Process Integration