SAP security note 1501631, "CO-OM: Potential Directory Traversal". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Potential Directory Traversal in the CO-OM component.
Solution
Refer to SAP Note 1497003 for additional information and instructions. The corrections from this note are required before implementing SAP Note 1501631.
Applying this note may cause the following side effect: SAP Note 2345064, Syntax Error in class CL_IM_EXT_CO_DATA_EXAMPLE – Implementation of SAP Note 1501631.
Reason and prerequisites
The programs in the correction instructions contain vulnerabilities that could allow unauthorized access to files on the server. This can lead to data leakage or system integrity issues.
CVSS
Score 0
References
This note refers to
Affected components
- CO-OM (Controlling > Overhead Cost Controlling)
- SAP_APPL versions 470, 500, 600, 602, 603, 604, 605
Full note on SAP: SAP Support Launchpad note 1501631
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
