Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Directory Traversal vulnerability in Business Partner, SAP security note 2312966

SAP Note 2312966

SAP security note 2312966, “Directory Traversal Vulnerability in Business Partner”, is a note. Below are the symptom and the affected software components.

Description

Symptom

A Directory Traversal vulnerability has been identified in the Business Partner – Master Data component of SAP. This vulnerability allows an attacker to exploit insufficient validation of path information provided by users, enabling them to pass characters that represent "traverse to parent directory" through the file APIs.

Potential Impacts:

  • Confidentiality: An attacker could read the content of arbitrary files on the remote server, potentially exposing sensitive data.
  • Integrity: An attacker could overwrite, delete, or corrupt arbitrary files on the remote server.

CVSS

Score 4.3 Vector: AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Affected components

  • SAP_ABA versions 700 to 75B

Full note on SAP: SAP Support Launchpad note 2312966

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More