Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CRIHO – Potential Directory Traversal, SAP security note 1601668

SAP Note 1601668
SAP Security Note

SAP security note 1601668, “CRIHO – Potential Directory Traversal”, released on November 8, 2011. Below are the symptom and SAP recommended solution.

ComponentIS-HER-CM-NL (Industry-Specific Components > Higher Education and Research > Student Lifecycle Management > Student Lifecycle Management – Netherlands)
TypeSAP Security Note
Version2
Released onNovember 8, 2011

Description

Symptom

This security note addresses a potential directory traversal vulnerability present in the following reports:

  • RHIQ_NL_CRIHO_COMPARE
  • RHIQ_NL_CRIHO_IBGHISTORY
  • RHIQ_NL_IBGTUIFEE_IN

A malicious user could exploit these vulnerabilities to read arbitrary files on the remote server, potentially disclosing confidential information.

Solution

To mitigate the vulnerability, apply the corrections from Note 1497003 first. Then, you can implement this note by either upgrading to the applicable Support Package, or applying the Correction Instructions attached to this note.

Reason and prerequisites

The programs affected contain vulnerabilities that allow unauthorized access to sensitive files. To implement this note, the corrections from Note 1497003 are a prerequisite.

Additionally, ensure that the following prerequisite notes are applied:

Full note on SAP: SAP Support Launchpad note 1601668

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More