SAP Security Note
SAP security note 1608307, “Directory traversal in IS-H-PA, IS-H-IS-GMS, IS-H-CM-OUT”. Below are the symptom and SAP recommended solution.
Description
Symptom
Potential directory traversal vulnerabilities exist in the following components:
- IS-H-PA
- IS-H-IS-GMS
- IS-H-CM-OUT
Solution
Ensure all corrections provided in Note 1497003 are implemented before applying this note.
Use transaction FILE to define logical file paths:
- Double-click “Logical File Path Definition, Cross-Client” in the tree on the left-hand side.
- Choose New Entries and enter the required data: Logical file: “RNAP21K01”; Name: “Validation for DRG Data P21 Procedure Information and Hospital Data”; Data format: “DIR”; Application area: “IS”.
- Save your changes.
Reason and prerequisites
The affected programs contain vulnerabilities that allow a malicious user to:
- Read arbitrary files on the remote server, potentially disclosing confidential information.
- Write arbitrary files on the remote server, possibly corrupting data or altering system behavior.
References
- 1607749 – Directory traversal in IS-H, central program part
- 1526102 – IS-H: Directory Traversal Vulnerability in IS-H
Full note on SAP: SAP Support Launchpad note 1608307
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
