SAP Security Note
High priority
SAP security note 1592786, "Directory traversal in CRM Web Channel applications", is a program error note released on 10.01.2012. Below are the symptom and SAP recommended solution.
Description
Symptom
Web Channel applications contain a vulnerability that allows an attacker to perform directory traversal. This vulnerability enables unauthorized reading of arbitrary files on the remote server, potentially disclosing confidential information.
Solution
This note provides Java corrections for E-Commerce and Web Channel. To address the vulnerability:
- Apply the Support Package patch level attached to this note.
- For more information on applying Java patches, refer to Note 877887.
- See Note 1546959 for information about the patch strategy.
Reason and prerequisites
Web Channel applications fail to correctly validate the path used to reference a file read from the remote server. As a result, an attacker can manipulate the program to access arbitrary files within the system, leading to potential data disclosure.
CVSS
Score 0
References
- 1546959: Patch strategies for SAP E-Commerce solutions
- 877887: Installing Patches for CRM Java Components and FSCM BD
Full note on SAP: SAP Support Launchpad note 1592786
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




