SAP Security Note
High priority
SAP security note 1615093, "Directory traversal in IS-H-CM", is a program error note released on 08.11.2011. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Potential directory traversal in the following components: IS-H-CM
Solution
Refer to Note 1497003 and Note 1607749. The corrections contained in these notes are prerequisites for this note.
Logical file names used in this solution:
- RNC301C3
- RNC301H3
- RNC302C0
- RNC301CHECKDATACOLLPOINTS
Recommendations for setting up logical file names: To avoid maintaining a high number of logical file names, some programs share the same logical file name. This creates dependencies among these programs. To securely separate data created by different users and programs, create a directory structure that reflects the user name and/or program name, and use this information when setting up the physical path and file names for the logical file paths and file names.
Reason and prerequisites
The programs specified in the correction instructions contain vulnerabilities that allow a malicious user to:
- Read arbitrary files on the remote server, potentially disclosing confidential information.
- Write arbitrary files on the remote server, possibly corrupting data or altering system behavior.
References
Affected components
- IS-H 463B to 605
Full note on SAP: SAP Support Launchpad note 1615093
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
