SAP Security Note
High Priority
SAP security note 1577512, "Update #1 to SAP Note 1546103 – Correction for Directory Traversal Vulnerability", is a program error note released on April 8, 2015. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Correction instructions in SAP Note 1546103 versions 1-4 introduce a security vulnerability (potential directory traversal). This vulnerability affects the following SAP releases:
- 46C
- 4.70
- 5.00
- 6.00
- 6.02
- 6.03
- 6.04
- 6.05
Solution
Implement this update note only if SAP Note 1546103 was downloaded and implemented before April 1st, 2011 (versions 4 or lower).
- Version 3: Mass Release.
- Version 4: Correction instruction (CI) regenerated for Support Pack (SP) adjustment.
Reason and prerequisites
SAP Note 1546103 contains correction instructions that are erroneous in note versions 4 or lower, leading to potential security vulnerabilities.
References
Affected components
- SAP_APPL 46C
- SAP_APPL 470
- SAP_APPL 500
- SAP_APPL 600
- SAP_APPL 602
- SAP_APPL 603
- SAP_APPL 604
- SAP_APPL 605
Full note on SAP: SAP Support Launchpad note 1577512
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




