SAP security note 1509869, "Market Data Interface: Potential Directory Traversal", is a program error note released on 14.12.2010. Below are the SAP recommended solution and the affected software components.
Description
Solution
To mitigate this vulnerability, apply the correction instructions provided in Note 1497003. These corrections are prerequisites for implementing this note.
References
Affected components
- Financial Supply Chain Management > Treasury and Risk Management > Basic Functions (FIN-FSCM-TRM-BF)
- Treasury > Treasury Management (TR-TM)
- Treasury > Risk Management > Master Data (TR-MRM-MD)
- Other related sub-components as detailed in the note.
Full note on SAP: SAP Support Launchpad note 1509869
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
