SAP Security Note
High priority
SAP security note 1511119, “ICM: Potential Directory Traversal”, is a program error note released on 14.12.2010. Below are the symptom, reason and prerequisites, SAP recommended solution, CVSS score, references and the affected software components.
Description
Symptom
Potential Directory Traversal in the following component:
- ICM-MD
Solution
Please refer to Note 1497003 for additional information and instructions. The corrections from Note 1497003 are a prerequisite for the implementation of this note.
Logical File Names Used in this Solution
ICM_SD_FILE_PATH_NAME
Logical File Paths Used in this Solution
All logical file names listed above use the logical file path ICM_SD_FILE_PATH.
Reason and prerequisites
The programs contained in the correction instructions contain vulnerabilities through which a malicious user can potentially read arbitrary files on the remote server, possibly disclosing confidential information. Some of the programs contained in the correction instructions contain a vulnerability through which a malicious user can potentially write arbitrary files on the remote server, possibly corrupting data or altering system behavior.
CVSS
Score 0
References
- 1837735 – Directory traversal in component ICM
- 1497003 – Potential directory traversals in applications
Affected components
- EA-APPL (600, 602, 603, 604, 605)
Full note on SAP: SAP Support Launchpad note 1511119
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



