SAP Security Note
Medium priority
SAP security note 1867210, "Directory traversal in BI-RA-CR", released on 13.08.2013. Below are the symptom and SAP recommended solution.
Description
Symptom
BI-RA-CR contains a vulnerability through which an attacker can potentially read arbitrary files on the remote server, possibly disclosing confidential information.
Solution
- XIR3 customers: Apply FixPack 5.5, 6.2, or SP7.
- BI 4.0 customers: Apply Patch 5.9, 6.2, or SP7.
Reason and prerequisites
Directory traversal: BI-RA-CR fails to correctly validate the file path used to reference a file read from the remote server. As a result, an attacker can potentially direct the program to an arbitrary other file in the system, disclosing its contents.
CVSS
Score 4.0 Vector: AV:N/AC:L/AU:S/C:P/I:N/A:N
Full note on SAP: SAP Support Launchpad note 1867210
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




