SAP security note 1630293, "Directory Traversal in the Portal", is a note. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
This security note has been updated. For more detailed information, see Security Note 1727173 and Security Note 1775705.
The Portal contains a vulnerability through which a malicious user can potentially read arbitrary files on the remote server, possibly disclosing confidential information.
Solution
Under the tab "SP Patch Level" within this security note you can check for the appropriate SP Patch Level fixing the security issue.
Reason and prerequisites
The Portal fails to correctly validate the path with which a file that is read from the remote server is referenced. Through this, an attacker can potentially point the program to an arbitrary other file on the system, disclosing its contents.
Side effects
This document is causing side effects: 1775705 – Update 2 to Security Note 1630293
CVSS
Score 4.9 Vector: AV:N/AC:H/AU:S/C:C/I:N/A:N
References
Affected components
- EP-PSERV: 7.00 to 7.02
- EP-PSERV: 6.0_640 to 6.0_640
- EP-RUNTIME: 7.10 to 7.11
- EP-RUNTIME: 7.20 to 7.20
- EP-APPS-EXT: 7.10 to 7.11
- EP-APPS-EXT: 7.20 to 7.20
- EP-APPS-EXT: 7.30 to 7.30
- EP-APPS-EXT: 7.31 to 7.31
Full note on SAP: SAP Support Launchpad note 1630293
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
