SAP security note 1584383, "Directory traversal in Bank Analyzer", is a note. Below are the symptom and SAP recommended solution.
Description
Symptom
Bank Analyzer contains a vulnerability through which a malicious user can potentially read arbitrary files on the remote server, possibly disclosing confidential information.
Solution
Please apply the following solution:
Reason and prerequisites
Bank Analyzer fails to correctly validate the path that is used to reference a file that is read from the remote server. As a result, a malicious user can potentially direct the program to an arbitrary other file in the system, disclosing its contents.
References
This note refers to
Full note on SAP: SAP Support Launchpad note 1584383
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
