Карточка уязвимости
Характеристики уязвимости
Уровень опасности
Оценка CVSS
(AV:N/AC:L/AU:N/C:C/I:C/A:CSAP)
Производитель ПО
Наименование ПО
SAP Notes
(1755108-5)
SAP Support Packages
(J2EE_ENGINE_SERVERCORE_710_SP012_000025, J2EE_ENGINE_SERVERCORE_710_SP013_000016, J2EE_ENGINE_SERVERCORE_710_SP014_000019, J2EE_ENGINE_SERVERCORE_710_SP015_000002, J2EE_ENGINE_SERVERCORE_710_SP016_000000, J2EE_ENGINE_SERVERCORE_710_SP999999_999999, J2EE_ENGINE_SERVERCORE_711_SP007_000025, J2EE_ENGINE_SERVERCORE_711_SP008_000021, J2EE_ENGINE_SERVERCORE_711_SP009_000021, J2EE_ENGINE_SERVERCORE_711_SP010_000003, J2EE_ENGINE_SERVERCORE_711_SP011_000000, J2EE_ENGINE_SERVERCORE_711_SP999999_999999, J2EE_ENGINE_SERVERCORE_720_SP005_000040, J2EE_ENGINE_SERVERCORE_720_SP006_000029, J2EE_ENGINE_SERVERCORE_720_SP007_000024, J2EE_ENGINE_SERVERCORE_720_SP008_000002, J2EE_ENGINE_SERVERCORE_720_SP009_000000, J2EE_ENGINE_SERVERCORE_720_SP999999_999999, J2EE_ENGINE_SERVERCORE_730_SP002_000030, J2EE_ENGINE_SERVERCORE_730_SP003_000030, J2EE_ENGINE_SERVERCORE_730_SP004_000026, J2EE_ENGINE_SERVERCORE_730_SP005_000039, J2EE_ENGINE_SERVERCORE_730_SP007_000023, J2EE_ENGINE_SERVERCORE_730_SP008_000000, J2EE_ENGINE_SERVERCORE_730_SP009_000000, J2EE_ENGINE_SERVERCORE_730_SP999999_999999, J2EE_ENGINE_SERVERCORE_731_SP002_000024, J2EE_ENGINE_SERVERCORE_731_SP003_000018, J2EE_ENGINE_SERVERCORE_731_SP004_000011, J2EE_ENGINE_SERVERCORE_731_SP005_000000, J2EE_ENGINE_SERVERCORE_731_SP006_000000, J2EE_ENGINE_SERVERCORE_731_SP999999_999999, SAP_J2EE_ENGINE_640_SP028_000017, SAP_J2EE_ENGINE_640_SP029_000011, SAP_J2EE_ENGINE_640_SP030_000003, SAP_J2EE_ENGINE_640_SP031_000000, SAP_J2EE_ENGINE_640_SP999999_999999, SAP_J2EE_ENGINE_CORE_640_SP031_000000, SAP_J2EE_ENGINE_CORE_640_SP999999_999999, SAP_J2EE_ENGINE_CORE_700_SP024_000019, SAP_J2EE_ENGINE_CORE_700_SP025_000017, SAP_J2EE_ENGINE_CORE_700_SP026_000015, SAP_J2EE_ENGINE_CORE_700_SP027_000004, SAP_J2EE_ENGINE_CORE_700_SP028_000000, SAP_J2EE_ENGINE_CORE_700_SP999999_999999, SAP_J2EE_ENGINE_CORE_701_SP009_000021, SAP_J2EE_ENGINE_CORE_701_SP010_000020, SAP_J2EE_ENGINE_CORE_701_SP011_000016, SAP_J2EE_ENGINE_CORE_701_SP012_000005, SAP_J2EE_ENGINE_CORE_701_SP013_000000, SAP_J2EE_ENGINE_CORE_701_SP999999_999999, SAP_J2EE_ENGINE_CORE_702_SP007_000023, SAP_J2EE_ENGINE_CORE_702_SP008_000022, SAP_J2EE_ENGINE_CORE_702_SP009_000021, SAP_J2EE_ENGINE_CORE_702_SP010_000017, SAP_J2EE_ENGINE_CORE_702_SP011_000020, SAP_J2EE_ENGINE_CORE_702_SP012_000002, SAP_J2EE_ENGINE_CORE_702_SP013_000000, SAP_J2EE_ENGINE_CORE_702_SP999999_999999)
Описание
The adminadapter service fails to correctly validate the path that is used for referring a file that is read from the remote server. As a result, an attacker can potentially direct the program to another arbitrary file in the system, disclosing its contents.The adminadapter service fails to correctly validate the path to which a user-submitted file is written. As a result, an attacker can potentially overwrite data in the remote system.Additionally, the adminadapter service does not contain authorization checks for checking the authenticated user's authorization in order to access some of its functions. This may result in undesired system behavior.
Как исправить
Apply Patch Level for your version and service pack that contains all the fixes attached to this note. For details, check validity section.
Ссылки