Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Directory traversal in Web Channel Experience Management, SAP security note 1743637

SAP Note 1743637
SAP Security Note
Medium priority

SAP security note 1743637, "Directory traversal in Web Channel Experience Management", is a note released on 12.02.2013. Below are the symptom, SAP recommended solution and the affected software components.

PriorityCorrection with medium priority
TypeSAP Security Note
StatusReleased for Customer
Released on12.02.2013

Description

Symptom

Directory traversal with read-only directory traversal: Apache MyFaces that is used by Web Channel Experience Management contains a vulnerability through which an attacker can potentially read arbitrary files on the remote server, possibly disclosing confidential information.

Solution

Import the Support Package patch level referenced in this SAP Note or import a higher level.

Reason and prerequisites

Apache MyFaces, utilized by Web Channel Experience Management, fails to correctly validate the path used to reference a file read from the remote server. Consequently, an attacker can potentially direct the application to access arbitrary files within the system, leading to the disclosure of their contents.

Affected components

  • SAP-WEC-FRW 2.0

Full note on SAP: SAP Support Launchpad note 1743637

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More