SAP security note 2312966, “Directory Traversal Vulnerability in Business Partner”, is a note. Below are the symptom and the affected software components.
Description
Symptom
A Directory Traversal vulnerability has been identified in the Business Partner – Master Data component of SAP. This vulnerability allows an attacker to exploit insufficient validation of path information provided by users, enabling them to pass characters that represent "traverse to parent directory" through the file APIs.
Potential Impacts:
- Confidentiality: An attacker could read the content of arbitrary files on the remote server, potentially exposing sensitive data.
- Integrity: An attacker could overwrite, delete, or corrupt arbitrary files on the remote server.
CVSS
Score 4.3 Vector: AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Affected components
- SAP_ABA versions 700 to 75B
Full note on SAP: SAP Support Launchpad note 2312966
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
