SAP Security Note
High priority
SAP security note 1659893, "Update #1 to Security Note 1598791", is a consulting note released on 02.12.2011. Below are the symptom and SAP recommended solution.
Description
Symptom
Correction instructions provided for the vulnerability (Directory Traversal) addressed in Security Note 1598699 must be corrected for the following releases:
- ERP 2005 Enhancement Pack 4 (6.04)
- ERP 2005 (6.00)
- ERP 2004 (5.00)
- R/3 Enterprise (4.70)
- R/3 Enterprise (4.6C)
Solution
If you have applied Security Note 1598699 manually via SNOTE, ensure that the Manual Pre-Implementation Steps were carried out and perform any steps that have not been completed.
Reason and prerequisites
Security Note 1598699 contains correction instructions which are erroneous.
CVSS
Score 0
References
Full note on SAP: SAP Support Launchpad note 1659893
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
