SAP Security Note
Medium priority
SAP security note 1875158, "Directory traversal in CRM-MD-SDB", is a program error note released on August 13, 2013. Below are the symptom and SAP recommended solution.
Description
Symptom
CRM-MD-SDB contains a vulnerability that allows an attacker to write arbitrary files to the remote server, potentially corrupting data or altering system behavior.
Solution
Refer to Note 1497003 for additional information and instructions. Implementing the corrections from this note is a prerequisite for applying this security note.
Logical file name used in this solution: SDB_CMS_ATTACHMENT_LFN (SDB Content Management Service Upload), physical file DIR, data format DIR, logical path /SDB/CMSATTACHMENT.
Reason and prerequisites
CRM-MD-SDB fails to correctly validate the file path used to reference files read from the remote server. This allows an attacker to direct the program to access arbitrary files on the system, leading to potential disclosure of their contents.
References
This note refers to
Full note on SAP: SAP Support Launchpad note 1875158
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
