SAP security note 1518284, "EWM: Potential Directory Traversal", is a program error note released on December 14, 2010. Below are the symptom, SAP recommended solution, reason and prerequisites and references.
Description
Symptom
Potential Directory Traversal vulnerabilities exist in the following transactions:
- /SCWM/SBUP (Report /SCWM/TLAGP_UPLOAD)
- /SCWM/SRTUP (Report /SCWM/TLAGPS_UPLOAD)
- /SCWM/ISU (Report /SCWM/R_INITIALSTOCKUPLOAD)
- /SCWM/MS_RESULT (Report /SCWM/R_MS_RESULT_READ), relevant from release 5.1 onwards
- /SCWM/ELS_UPLOAD (Report /SCWM/ELS_UPLOAD), relevant from release 5.1 onwards
Solution
- For Release EWM 5.0 (SCM 5): only local filenames can be used in the above transactions; implement the correction instruction to disable access to the application server; handling of logical filenames is not necessary.
- For Release SCM 5.1 and above (SCMEWM 5.1+): refer to Note 1497003 for additional information and instructions; corrections from this note are a prerequisite for implementing this note.
Reason and prerequisites
The programs contained in the correction instructions have vulnerabilities that allow a malicious user to potentially read arbitrary files on the remote server, potentially disclosing confidential information.
References
Full note on SAP: SAP Support Launchpad note 1518284
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



