SAP Security Note
Medium priority
SAP security note 1510756, “CDMC(ST-PI SP00-SP03): Potential Directory Traversal”, is a program error note released on 14.12.2010. Below are the symptom, reason and prerequisites, the SAP recommended solution, CVSS, references and the affected software components.
Description
Symptom
Potential directory traversal in the component SV-SMG-CDMC.
Solution
Please refer to Note 1498832 for additional information and instructions. The corrections from Note 1498832 are a prerequisite for the implementation of this note.
Reason and prerequisites
The programs contained in the correction instructions contain vulnerabilities through which a malicious user can potentially read arbitrary files on the remote server, possibly disclosing confidential information.
Some of the programs contained in the correction instructions contain a vulnerability through which a malicious user can potentially write arbitrary files on the remote server, possibly corrupting data or altering system behavior.
CVSS
Score 0
References
- 1509340 – Collective Note with all corrections for CDMC (ST-PI SP03)
- 1348772 – CDMC Corrections – Composite SAP Note
Affected components
- ST-PI 2008_1_46C
- ST-PI 2008_1_620
- ST-PI 2008_1_640
- ST-PI 2008_1_700
- ST-PI 2008_1_710
Full note on SAP: SAP Support Launchpad note 1510756
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



