Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

LO-MD-MM Directory traversal vulnerability, SAP security note 1532325

SAP Note 1532325

SAP security note 1532325, "LO-MD-MM: Directory traversal vulnerability", is a note. Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

The component LO-MD-MM contains a directory traversal vulnerability. Affected program: RMMMBIM0.

Solution

Implement the attached correction instructions provided in the note. For additional information and instructions, refer to Note 1497003. The corrections in Note 1497003 are a prerequisite for implementing this note.

  • Logical file name: MATERIAL_MASTER_BTCI_LOG
  • Program using logical file name: RMMMBIM0
  • Logical file path: LO_MD_ROOT

Refer to Note 1498832 for additional information on setting up logical file names related to file name validation.

Reason and prerequisites

The program RMMMBIM0 has vulnerabilities that allow a malicious user to potentially read arbitrary files on the remote server, which may lead to the disclosure of confidential information.

CVSS

Score 0

References

Affected components

  • SAP_APPL 31I to 605

Full note on SAP: SAP Support Launchpad note 1532325

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More