SAP Security Note
Medium priority
SAP security note 1786732, "Directory traversal in J1BA", is a program error note released on 04.08.2017. Below are the symptom and SAP recommended solution.
Description
Symptom
Read-write or write directory traversal: J1BA contains a vulnerability through which an attacker can potentially write arbitrary files to the remote server, possibly corrupting data or altering system behavior.
Solution
The solution is available with the next Support Package. Alternatively, you can implement the correction instruction for your release.
Reason and prerequisites
Read-write or write directory traversal: J1BA fails to correctly validate the path to which a user-submitted file is written. As a result, an attacker can potentially overwrite data in the remote system.
Full note on SAP: SAP Support Launchpad note 1786732
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



