SAP security note 1585527, “Directory traversal in CRM Web channel”, is a note. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
A malicious user with admin access can exploit a directory traversal vulnerability in the logging section of CRM Web Channel applications. This can allow the attacker to reference and read arbitrary files on the system, potentially exposing sensitive data.
Solution
SAP has introduced new security checks in the logging section of the CRM Web Channel applications’ admin area:
- Path Validation: Log files or directories must reside within the J2EE server’s root directory, for example: Linux/Unix:
/usr/sap/[SID]/JC00/j2ee/cluster/serverX/, Windows:D:\usr\sap\[SID]\JCOO\j2ee\cluster\serverX\ - File Extension Restriction: Only log files with the following extensions can be created, viewed, or downloaded:
.log,.trc,.zip
CVSS
Score 2.1 Vector: AV:N/AC:H/AU:S/C:P/I:N/A:N
References
- Patch strategies for SAP E-Commerce solutions (Note 1546959)
- Installing Patches for CRM Java Components and FSCM BD (Note 877887)
Affected components
- SAP-SHRJAV
- ESALES_Base
Full note on SAP: SAP Support Launchpad note 1585527
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
