SAP Security Note
High priority
SAP security note 1575006, “Directory Traversal in SPOOL System”, is a program error note released on 19.10.2011. Below are the symptom and SAP recommended solution.
Description
Symptom
SPOOL System contains a vulnerability through which a malicious user can potentially write arbitrary files on the remote server, possibly corrupting data or altering system behaviour.
Solution
Please apply the support package mentioned in this note at least, or the respective correction instruction.
Reason and prerequisites
SPOOL System fails to correctly validate the path to which a user-submitted file is written. As a result, a malicious user can potentially overwrite data in the remote system.
References
- Note 888889 – Automatic checks for security notes using RSECNOTE (outdated)
- Note 1525998 – Printing ADS documents does not work after transport
Full note on SAP: SAP Support Launchpad note 1575006
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
