SAP security note 1898735, "Directory traversal vulnerability in CCMS agents", is a note. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
CCMS agents contain a vulnerability that can be exploited to write arbitrary files to the remote server.
Solution
Update the standalone CCMS agents sapccm4x and sapccmsr in the SAP Kernel using binaries from CCMAGENT.SAR. Ensure that you apply the correct support package patches as outlined in the note. Refer to the Support Package Patches section for detailed patch information.
CVSS
Score 4.9 Vector: AV:N/AC:M/AU:S/C:N/I:P/A:P
References
This note refers to
Referenced by
Affected components
- Various kernel versions including 7.20, 7.21, 7.40, and 7.41 for both 32-bit and 64-bit systems
Full note on SAP: SAP Support Launchpad note 1898735
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



