Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CA-DMS Potential Directory Traversal, SAP security note 1600879

SAP Note 1600879
SAP Security Note
High priority

SAP security note 1600879, "CA-DMS: Potential Directory Traversal", is a note released on February 14, 2012. Below are the symptom, SAP recommended solution and reason and prerequisites.

ComponentCross-Application Components > Document Management (CA-DMS)
PriorityCorrection with high priority
TypeSAP Security Note
Version3
StatusReleased for Customer
Released onFebruary 14, 2012

Description

Symptom

The Document Management System (DMS) contains a vulnerability that allows a malicious user to potentially write arbitrary files on the remote server. This could lead to data corruption or alteration of system behavior.

Solution

Refer to SAP Note 1497003 for additional information and instructions. The corrections from this note are a prerequisite for implementing the security fix described in this note.

Reason and prerequisites

Certain function modules and subroutines in Document Management fail to validate the path where a user-submitted file is written. This oversight allows an attacker to overwrite data on the remote system.

Prerequisite: SAP Note 1497003 – Potential directory traversals in applications.

References

Full note on SAP: SAP Support Launchpad note 1600879

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More