SAP security note 1771149, “Directory traversal in FS-CM: Claims Management”, is a note. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
FS-CM contains a vulnerability that allows an attacker to perform directory traversal, potentially writing arbitrary files to the remote server, corrupting data, or altering system behavior.
Solution
Implement the correction instructions provided in the note or import the relevant Support Package.
Reason and prerequisites
FS-CM fails to correctly validate the path for user-submitted files, enabling attackers to overwrite data in the remote system.
References
Referenced by
Affected components
- INSURANCE 464
- INSURANCE 471
- INSURANCE 472
- INSURANCE 600
- INSURANCE 602
- INSURANCE 603
- INSURANCE 604
- INSURANCE 605
- INSURANCE 606
- INSURANCE 616
Full note on SAP: SAP Support Launchpad note 1771149
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
