SAP security note 1509654, "FI: Potential Directory Traversal – Turkey". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
A potential Directory Traversal exists in the following component: XX-CSC-TR.
Solution
To address this issue, please refer to SAP Note 1497003 for additional information and instructions. The corrections from Note 1497003 are a prerequisite for implementing this note.
Reason and prerequisites
Some programs included in the correction instructions contain a vulnerability that allows a malicious user to potentially write arbitrary files on the remote server. This could lead to data corruption or altered system behavior.
Affected components
- SAP_APPL: Versions 46C, 470, 500, 600, 602, 603, 604, 605
Full note on SAP: SAP Support Launchpad note 1509654
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
