SAP security note 1610663, "Directory traversal in Digital Asset Management", is a program error note released on 08.11.2011. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Potential directory traversal in the following components: Digital Asset Management.
Solution
For additional information and instructions, see Note 1497003. The corrections provided in Note 1497003 are a prerequisite for implementing this note.
Reason and prerequisites
The programs specified in the correction instructions contain vulnerabilities through which a malicious user can potentially read arbitrary files on the remote server, possibly disclosing confidential information.
Some of the programs specified in the correction instructions contain a vulnerability through which a malicious user can potentially write arbitrary files on the remote server, possibly corrupting data or altering system behavior.
Affected components
- BBPCRM
Full note on SAP: SAP Support Launchpad note 1610663
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
