Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

MANAD Potential Directory Traversal, SAP security note 1598360

SAP Note 1598360

SAP security note 1598360, “MANAD: Potential Directory Traversal”, released on November 8, 2011. Below are the symptom, SAP recommended solution and the affected software components.

Released onNovember 8, 2011

Description

Symptom

Vulnerability: potential directory traversal in XX-CSC-BR-REP.

Affected programs:

  • J_1BMANAD
  • LJ1B_FI_EXTRACTF01

Solution

To remediate this vulnerability:

  • Apply corrections from Note 1497003: these corrections are prerequisites for implementing Security Note 1598360.
  • Implement the corrections following the detailed instructions provided in the correction instructions linked within the note.

Reason and prerequisites

Certain programs specified in the correction instructions contain a vulnerability that could allow a malicious user to write and delete arbitrary files on the remote server. Implementing this security note requires applying corrections from Note 1497003.

CVSS

Score 0

References

Affected components

  • SAP_APPL (versions 46C to 605)

Full note on SAP: SAP Support Launchpad note 1598360

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More