SAP security note 1635004, “Directory Traversal in BC-SRV-KPR”, is a program error note released on 10.04.2012. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Read-write directory traversal in BC-SRV-KPR contains a vulnerability through which a malicious user can potentially write arbitrary files on the remote server, possibly corrupting data or altering system behavior.
Solution
Refer to note 1497003 for additional information and instructions. The corrections from note 1497003 are a prerequisite for implementation of this note.
Logical file names used in this solution: the following logical file name has been created to enable the validation of physical file names:
- KPRO_IMPORT_EXPORT
Reason and prerequisites
Read-write directory traversal in BC-SRV-KPR fails to correctly validate the path a user-submitted file is written to. Through this, an attacker can potentially overwrite data on the remote system.
References
Referenced by
Affected components
- SAP_BASIS 46C to 46D
- SAP_BASIS 610 to 640
- SAP_BASIS 700 to 702
- SAP_BASIS 710 to 730
- SAP_BASIS 731
Full note on SAP: SAP Support Launchpad note 1635004
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
