SAP security note 1506736, "CML: Potential Directory Traversal", is a program error note released on December 14, 2010. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
FS-CML (US specific payment processing) contains a vulnerability that allows a malicious user to potentially write arbitrary files on the remote server. This could lead to data corruption or alteration of system behavior.
Solution
Refer to SAP Note 1497003 for additional information and instructions. Implementing the corrections from this note is a prerequisite for applying the fixes in SAP Note 1506736.
Programs using the logical file names:
- CML_PAYMENT_US: RFVD_AUTODRAFT_PROCESS, RFVD_PAY_STOP
- CML_CREDIT_BUREAU: RFVD_CBR_PROCESS
Logical file path used: CML_ROOT.
References
Affected components
- EA-FINSERV: 600, 603, 604, 605
Full note on SAP: SAP Support Launchpad note 1506736
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
