SAP Security Note
High priority
SAP security note 1513064, "Directory Traversal in BC-CTS-LAN", is a program error note released on December 14, 2010. Below are the symptom and the SAP recommended solution.
Description
Symptom
The component BC-CTS-LAN contains a vulnerability that allows a malicious user to potentially delete arbitrary files on the server, which could alter system behavior.
Solution
Implement the correction instructions using the SAP Note Assistant to apply the necessary corrections, and import the relevant Support Package appropriate for your release.
Reason and prerequisites
The function in BC-CTS-LAN fails to correctly validate the path where a user-submitted file is written. This oversight allows an attacker to delete files on the remote system.
Full note on SAP: SAP Support Launchpad note 1513064
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



