SAP security note 2156556, "Directory traversal in module pool SAPMJ1GFBWE", is a note. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Module pool SAPMJ1GFBWE contains a vulnerability through which an attacker can potentially read arbitrary files on the remote server, possibly disclosing confidential information.
Solution
As a general rule, SAP recommends that you install a solution by applying a Support Package. However, if you need to install a solution earlier, use the Note Assistant to implement the correction instruction.
You can find more information about the Note Assistant in SAP Service Marketplace, under service.sap.com/note-assistant.
Reason and prerequisites
Module pool SAPMJ1GFBWE fails to correctly validate the path that is used to reference a file that is read from the remote server. As a result, an attacker can potentially direct the program to an arbitrary other file in the system, disclosing its contents.
Affected components
- Miscellaneous > Country/Region-Specific Developments > Greece > use FI-LOC-FI-GR
- C-CEE 110_600
- C-CEE 110_602
- C-CEE 110_603
- C-CEE 110_604
- C-CEE 110_700
- C-CEE 110_720
Full note on SAP: SAP Support Launchpad note 2156556
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
