Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

IS-H Directory Traversal Vulnerability in IS-H, SAP security note 1510407

SAP Note 1510407

SAP security note 1510407, "IS-H: Directory Traversal Vulnerability in IS-H". Below are the symptom and the SAP recommended solution.

Description

Symptom

IS-H contains a vulnerability that allows a malicious user to read or write arbitrary files on the remote server. This can lead to data corruption or alteration of system behavior.

IS-H fails to correctly validate the path where a user-submitted file is written. An attacker can exploit this to overwrite data on the remote system.

Solution

  • Implement Support Package 04 for EHP5.
  • Refer to SAP Note 1497003 for additional information and instructions. The corrections from this note are a prerequisite for implementing this note.

Reason and prerequisites

This note may cause side effects related to SAP Note 1607749, Directory traversal in IS-H, central program part.

References

Full note on SAP: SAP Support Launchpad note 1510407

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More