SAP Security Note
High priority
SAP security note 1600879, "CA-DMS: Potential Directory Traversal", is a note released on February 14, 2012. Below are the symptom, SAP recommended solution and reason and prerequisites.
Description
Symptom
The Document Management System (DMS) contains a vulnerability that allows a malicious user to potentially write arbitrary files on the remote server. This could lead to data corruption or alteration of system behavior.
Solution
Refer to SAP Note 1497003 for additional information and instructions. The corrections from this note are a prerequisite for implementing the security fix described in this note.
Reason and prerequisites
Certain function modules and subroutines in Document Management fail to validate the path where a user-submitted file is written. This oversight allows an attacker to overwrite data on the remote system.
Prerequisite: SAP Note 1497003 – Potential directory traversals in applications.
References
- SAP Note 1725378 – Path evaluation for SAPFTP functionality in CA-DMS
- SAP Note 1497003 – Potential directory traversals in applications
Full note on SAP: SAP Support Launchpad note 1600879
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
