SAP security note 2077260, "Directory Traversal in IM Summarization Reporting". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
IM Summarization Reporting contains a vulnerability that allows attackers to:
- Read Arbitrary Files: Potentially disclosing confidential information by accessing unauthorized files on the remote server.
- Write Arbitrary Files: Potentially corrupting data or altering system behavior by writing unauthorized files to the remote server.
Solution
To mitigate this vulnerability, implement the corrections provided in this security note. Additionally, refer to SAP Note 1497003 for further information and instructions, as it is a prerequisite for implementing this security note.
Reason and prerequisites
IM Summarization Reporting fails to correctly validate file paths, allowing attackers to reference arbitrary files within the system. This can lead to:
- Unauthorized File Access: Disclosing the contents of sensitive files.
- Data Corruption: Overwriting critical system files, leading to potential data loss or altered system behavior.
CVSS
Score 3.8
Affected components
- SAP_APPL: 600, 602, 603, 604, 605, 606, 616
- SAP_FIN: 617, 700
Full note on SAP: SAP Support Launchpad note 2077260
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
