High priority
SAP security note 1536809, "Directory Traversal in Physical Inventory Processing", is a program error note released on 14.12.2010. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
SAP Security Note 1536809 addresses a potential Directory Traversal vulnerability in the component SCM-EWM-PI. This vulnerability affects the following transactions:
/SCWM/PI_UPLOAD– Upload Storage Bins and Count Data/SCWM/PI_DOWNLOAD– Download Storage Bins and Count Data/SCWM/PI_SAMP_STOCK– Download Stock Population/SCWM/PI_SAMP_CR– Upload Sample to Create PI Documents/SCWM/PI_SAMP_UPDATE– Download Results or Stock Population
A malicious user can potentially read arbitrary files on the remote server, possibly disclosing confidential information. A malicious user can potentially write arbitrary files on the remote server, possibly corrupting data or altering system behavior.
Solution
Prerequisites: Ensure that SAP Note 1497003 is implemented as it contains prerequisites for this security note.
Correction Instructions: Apply the correction instructions provided in this note. Logical file names have been created to validate physical file names for the affected transactions. Refer to the respective notes for more information:
- Transaction
/SCWM/PI_SAMP_CR: Logical filename =EWM_PI_SAMP_CR(Note 1470669) - Transaction
/SCWM/PI_SAMP_STOCK: Logical filename =EWM_PI_SAMP_DOWNLOAD(Note 1470669) - Transaction
/SCWM/PI_SAMP_UPDATE: Logical filename =EWM_PI_SAMP_UPDATE(Note 1470669) - Transaction
/SCWM/PI_UPLOAD: Logical filename =EWM_PI_UPLOAD(Note 1452989) - Transaction
/SCWM/PI_DOWNLOAD: Logical filename =EWM_PI_DOWNLOAD(Note 1452989)
References
- Potential directory traversals in applications (Note 1497003)
- Physical inventory (PI) sampling: Logical file name (Note 1470669)
- Improvements in Download/Upload transactions. Performance (Note 1422197)
Affected components
- SCM: Versions 500
- SCMEWM: Versions 510, 700, 701
Full note on SAP: SAP Support Launchpad note 1536809
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
