SAP security note 1501874, "Investment Management: Potential Directory Traversal". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
A potential directory traversal vulnerability has been identified in the Investment Management (IM) component. This vulnerability allows a malicious user to write arbitrary files on the remote server, which could lead to data corruption or alteration of system behavior.
Solution
Refer to SAP Note 1497003 for additional information and instructions. Implementing the corrections from SAP Note 1497003 is a prerequisite for applying this security note.
Reason and prerequisites
The vulnerability exists due to flaws in the programs contained within the correction instructions. These flaws can be exploited to write arbitrary files on the server, posing a significant security risk.
Affected components
- Investment Management > Spec. investments > Investment Program (IM-FA-IP)
Full note on SAP: SAP Support Launchpad note 1501874
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
