Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Directory traversal in CRM_EDR_UPLOAD_DATA/-DOWNLOAD_DATA, SAP security note 1484712

SAP Note 1484712
SAP Security Note

SAP security note 1484712, "Directory traversal in CRM_EDR_UPLOAD_DATA/-DOWNLOAD_DATA", was released on 10.08.2010. Below are the symptom, SAP recommended solution and the affected software components.

ComponentCRM-BTX-PRV
TypeSAP Security Note
Version1
StatusReleased for Customer
Released on10.08.2010

Description

Symptom

An error in CRM_EDR_UPLOAD_DATA or CRM_EDR_DOWNLOAD_DATA allows data to be read and written across the network.

Solution

Implement the attached corrections.

Reason and prerequisites

CRM_EDR_UPLOAD_DATA or CRM_EDR_DOWNLOAD_DATA displays an error during the check of paths to which data that is transferred by a user is written. An attacker can use this to transfer data to the remote system or to possibly overwrite existing data.

References

Affected components

  • BBPCRM versions 600, 700, 701

Full note on SAP: SAP Support Launchpad note 1484712

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More