SAP Security Note
High priority
SAP security note 1566528, "Directory traversal in IS-M", is a program error note released on October 11, 2011. Below are the symptom and SAP recommended solution.
Description
Symptom
Potential directory traversal in the component IS-M.
Solution
For detailed instructions, refer to Notes 1497003 and 1605703. Implementing the corrections from Note 1497003 is a prerequisite for this note.
After implementing the correction instructions from Note 1605703, execute the program RSFILECR. This program creates the necessary logical file names and records the changes in a transport request.
Reason and prerequisites
The programs specified in the correction instructions contain vulnerabilities that allow a malicious user to potentially read arbitrary files on the remote server, possibly disclosing confidential information. Additionally, some programs may allow writing arbitrary files, potentially corrupting data or altering system behavior.
References
- 1605703: RSFILECR: Potential directory traversals in applications
- 1590933: FM FILE_LOGFILE_ALIAS_PBO doesn’t return correct values
- 1543851: Potential directory traversals in applications
- 1507733: Directory Traversal in IS-Media
- 1497003: Potential directory traversals in applications
Full note on SAP: SAP Support Launchpad note 1566528
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
