Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Directory traversal in J1BA, SAP security note 1786732

SAP Note 1786732
SAP Security Note
Medium priority

SAP security note 1786732, "Directory traversal in J1BA", is a program error note released on 04.08.2017. Below are the symptom and SAP recommended solution.

ComponentXX-CSC-BR – Miscellaneous > Country/Region-Specific Developments > Brazil
CategoryProgram error
PriorityMedium priority
TypeSAP Security Note
Version2
StatusReleased for Customer
Released on04.08.2017
LanguageEnglish

Description

Symptom

Read-write or write directory traversal: J1BA contains a vulnerability through which an attacker can potentially write arbitrary files to the remote server, possibly corrupting data or altering system behavior.

Solution

The solution is available with the next Support Package. Alternatively, you can implement the correction instruction for your release.

Reason and prerequisites

Read-write or write directory traversal: J1BA fails to correctly validate the path to which a user-submitted file is written. As a result, an attacker can potentially overwrite data in the remote system.

Full note on SAP: SAP Support Launchpad note 1786732

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More