Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Change access to a file allowed in product control, SAP security note 1509975

SAP Note 1509975

SAP security note 1509975, "Change access to a file allowed in product control". Below are the symptom and SAP recommended solution.

Description

Symptom

A directory traversal vulnerability exists in the Product Control summary report, allowing a malicious user to potentially change arbitrary files on the application server, which may lead to data corruption.

Solution

The selection screen parameter is functionally redundant. Code changes have been made to remove the related code. Please apply the correction instructions and correction instructions to fix the issue.

Reason and prerequisites

The report permits inputting a filename via a selection screen parameter. This vulnerability allows an attacker to overwrite data of an existing file.

References

Full note on SAP: SAP Support Launchpad note 1509975

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More