SAP Security Note
Medium priority
SAP security note 1504203, "CM: Potential Directory Traversal ICL_DIAG_UPLOAD", is a program error note released on 14.12.2010. Below are the symptom and SAP recommended solution.
Description
Symptom
Potential Directory Traversal in the program ICL_DIAG_UPLOAD.
Solution
Refer to SAP Note 1497003 for additional information and instructions. The corrections from note 1497003 are prerequisites for implementing this note.
The logical file name ICLDIAG is used in this solution, using the logical file path ICLDIAG.
Reason and prerequisites
The programs included in the correction instructions contain vulnerabilities that may allow a malicious user to read arbitrary files on the remote server, potentially disclosing confidential information. Additionally, some programs may allow writing arbitrary files on the remote server, which could lead to data corruption or altered system behavior.
Full note on SAP: SAP Support Launchpad note 1504203
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



