SAP Knowledge Base Article - Preview

3800315 - 'Unrestricted File Upload' vulnerability - BPC

Symptom

Users are able to upload files to the SAP Business Planning and Consolidation (BPC) application through the file-upload functionality without the expected virus scanning and MIME-type validation.

During a security assessment or penetration test, it may be possible to upload file types that should normally be restricted, such as HTML files containing client-side scripting code.

The behavior can be observed with the following BPC endpoints:

  • /sap/bw/cs/fileupload
  • /sap/bw/cs/user?method=set_image&category=user_profile
  • /sap/bw/cs/user?method=get_image&category=user_profile&hit=0

Applying SAP Note 3275841 - [CVE-2023-23851] Unrestricted File Upload in SAP Business Planning and Consolidation does not resolve the issue.


Read more...

Environment

  • SAP Business Planning and Consolidation 11.1, version for SAP BW/4HANA
  • SAP Business Planning and Consolidation 2021, version for SAP BW/4HANA

Product

SAP BW/4HANA 2021 ; SAP Business Planning and Consolidation 11.1, version for SAP BW/4HANA ; SAP Business Planning and Consolidation 2021, version for SAP BW/4HANA

Keywords

BPC, SAP Business Planning and Consolidation, file upload, unrestricted file upload, virus scan, Virus Scan Interface, VSI, CL_VSI, Virus Scan Adapter, VSA, MIME type, VSCAN, VSCANPROFILE, RSBPC0ADMIN, CVE-2023-23851, SAP Note 3275841 , KBA , EPM-BPC-BW4-INF , BPC/4 - Infrastructure , Problem

About this page

This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).

Search for additional results

Visit SAP Support Portal's SAP Notes and KBA Search.