Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Directory traversal in IM summarization reporting, SAP security note 2077260

SAP Note 2077260

SAP security note 2077260, "Directory Traversal in IM Summarization Reporting". Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

IM Summarization Reporting contains a vulnerability that allows attackers to:

  • Read Arbitrary Files: Potentially disclosing confidential information by accessing unauthorized files on the remote server.
  • Write Arbitrary Files: Potentially corrupting data or altering system behavior by writing unauthorized files to the remote server.

Solution

To mitigate this vulnerability, implement the corrections provided in this security note. Additionally, refer to SAP Note 1497003 for further information and instructions, as it is a prerequisite for implementing this security note.

Reason and prerequisites

IM Summarization Reporting fails to correctly validate file paths, allowing attackers to reference arbitrary files within the system. This can lead to:

  • Unauthorized File Access: Disclosing the contents of sensitive files.
  • Data Corruption: Overwriting critical system files, leading to potential data loss or altered system behavior.

CVSS

Score 3.8

Affected components

  • SAP_APPL: 600, 602, 603, 604, 605, 606, 616
  • SAP_FIN: 617, 700

Full note on SAP: SAP Support Launchpad note 2077260

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More