SAP security note 1530895, "Transaction IBIP: Potential Directory Traversal". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Potential Directory Traversal in the transaction IBIP, component PM.
Solution
Refer to SAP Note 1497003 for additional information and instructions. The corrections from this note are a prerequisite for implementing this note.
Logical file name used in this solution: IBIP_LOG_FILE.
Reason and prerequisites
The programs contain vulnerabilities that allow a malicious user to potentially read arbitrary files on the remote server, possibly disclosing confidential information. Some programs allow writing arbitrary files on the remote server, which could result in data corruption or altered system behavior.
References
- SAP Note 1510543 – Not allowed functions in trx. IBIP
- SAP Note 1497003 – Potential directory traversals in applications
Affected components
- SAP_APPL: 40B to 605
- SAP_BASIS: 46B to 710
Full note on SAP: SAP Support Launchpad note 1530895
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



