High priority
SAP security note 2043506, "Solution Manager File System Browser – Restrict File Content Access", is a note released on September 9, 2014. Below are the symptom and SAP recommended solution.
Description
Symptom
Using the File System Browser application, users might potentially have read and download access to sensitive files such as certificates.
Solution
Deploy the LM-SERVICE Java component where the issue is fixed.
This correction introduces a new whitelist property in the agelet configuration com.sap.smd.agent.application.filesystem: smd.white.list.extensions.
- Files with extensions not in the whitelist will still appear in the File System Browser but their content can no longer be displayed or downloaded.
- Editing the whitelist requires the SAP_RCA_AGT_ADM administrative role.
Full note on SAP: SAP Support Launchpad note 2043506
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



