Symptom
Users are able to upload files to the SAP Business Planning and Consolidation (BPC) application through the file-upload functionality without the expected virus scanning and MIME-type validation.
During a security assessment or penetration test, it may be possible to upload file types that should normally be restricted, such as HTML files containing client-side scripting code.
The behavior can be observed with the following BPC endpoints:
- /sap/bw/cs/fileupload
- /sap/bw/cs/user?method=set_image&category=user_profile
- /sap/bw/cs/user?method=get_image&category=user_profile&hit=0
Applying SAP Note 3275841 - [CVE-2023-23851] Unrestricted File Upload in SAP Business Planning and Consolidation does not resolve the issue.
Read more...
Environment
- SAP Business Planning and Consolidation 11.1, version for SAP BW/4HANA
- SAP Business Planning and Consolidation 2021, version for SAP BW/4HANA
Product
Keywords
BPC, SAP Business Planning and Consolidation, file upload, unrestricted file upload, virus scan, Virus Scan Interface, VSI, CL_VSI, Virus Scan Adapter, VSA, MIME type, VSCAN, VSCANPROFILE, RSBPC0ADMIN, CVE-2023-23851, SAP Note 3275841 , KBA , EPM-BPC-BW4-INF , BPC/4 - Infrastructure , Problem
About this page
This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).Search for additional results
Visit SAP Support Portal's SAP Notes and KBA Search.
SAP Knowledge Base Article - Preview