SAP security note 1957910, "Directory traversal in BC-CCM-FIL". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
BC-CCM-FIL contains a vulnerability that allows an attacker to potentially read arbitrary files on the remote server, possibly disclosing confidential information.
Solution
Implement the code corrections provided in SAP Note 1957910. Alternatively, apply the Support Packages mentioned in this SAP Note.
Reason and prerequisites
The function FILE_VALIDATE_NAME fails to correctly validate the file path used to reference a file read from the remote server. As a result, an attacker can direct the program to arbitrary files in the system, disclosing their contents.
References
Affected components
- SAP_BASIS: Versions 700 to 750
Full note on SAP: SAP Support Launchpad note 1957910
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
