Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Directory Traversal in MM-PUR-VM-SET, SAP security note 1521099

SAP Note 1521099SAP Security NoteHigh priority

SAP security note 1521099, "Directory Traversal in MM-PUR-VM-SET", is a program error note released on 14.12.2010. Below are the symptom and SAP recommended solution.

ComponentMaterials Management > Purchasing > Vendor-Material Relationships and Conditions > Subsequent Settlement
CategoryProgram error
PriorityCorrection with high priority
TypeSAP Security Note
Version3
StatusReleased for Customer
Released on14.12.2010
LanguageEnglish (Master Language: German)

Description

Symptom

There is a potential directory traversal in the component MM-PUR-VM-SET. The reports RWMBONF0 and RWMBONF2 contain vulnerabilities that allow a malicious user to access arbitrary files. Additionally, the report RWMBONF1 allows overwriting arbitrary files on the application server, leading to potential data deletion.

Solution

Refer to Note 1497003 for additional information. The corrections in this note are a prerequisite for implementing the solution for Note 1521099.

Key Actions:

  • Create Logical File Names: Use logical file name MM-PUR-VM-SET-MCKONAB to validate physical file names.
  • Maintain Physical Paths: Ensure the physical path for the logical path MM_PUR_VM_SET_PATH is correctly maintained using transaction FILE.
  • Update Programs: Apply the changes to programs RWMBONF0, RWMBONF1, and RWMBONF2 to use the validated paths.

CVSS

Score 0

References

Full note on SAP: SAP Support Launchpad note 1521099

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More