Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Directory traversal in AS Java Monitoring, SAP security note 2234971

SAP Note 2234971SAP Security NoteMedium priority

SAP security note 2234971, "Directory traversal in AS Java Monitoring", was released on 28.07.2016. Below are the symptom, SAP recommended solution and the affected software components.

ComponentBasis Components > NetWeaver Application Server Java > Local Admin Tools > Monitoring
PriorityCorrection with medium priority
TypeSAP Security Note
Version4
StatusReleased for Customer
Released on28.07.2016

Description

Symptom

AS Java Monitoring contains a vulnerability through which an attacker can potentially read arbitrary files on the remote server, possibly disclosing confidential information.

Solution

Update your AS Java to a fixed version and Support Package (SP). For more details, see the "SP Patch Level" section of this note.

CVSS

Score 5.8 / 10 Vector: AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N

References

Affected components

  • LM-CORE 7.10 – 7.11
  • LM-CORE 7.20
  • LM-CORE 7.30
  • LM-CORE 7.31
  • LM-CORE 7.40
  • LM-CORE 7.50

Full note on SAP: SAP Support Launchpad note 2234971

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More