SAP Security Note
High priority
SAP security note 1653738, "Update #1 to Security Note 1598699", released on 16.11.2011. Below are the symptom and SAP recommended solution.
Description
Symptom
This update corrects the vulnerability (Directory Traversal) addressed in Security Note 1598699. The correction instructions provided in the original note were erroneous and need to be amended for the following releases:
- ERP 2005 Enhancement Pack 4 (6.04)
- ERP 2005 (6.00)
- ERP 2004 (5.00)
- R/3 Enterprise (4.70)
Solution
If you have manually applied Security Note 1598699 via SNOTE, ensure that all Manual Pre-Implementation Steps have been carried out. Perform any steps that were not previously executed to properly address the vulnerability.
References
Full note on SAP: SAP Support Launchpad note 1653738
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
