SAP security note 1511552, "Directory Traversal / 8 issues/reopen in EDT", is a program error note released on 14.12.2010. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Potential Directory Traversal in the following components: IS-B-DP-EDT.
Solution
Refer to SAP Note 1497003 for additional information and instructions; the corrections from that note are a prerequisite for implementing this note.
Logical file names used in this solution:
- EDT_FILE_PATH_LOGICAL, which uses the logical file path EDT_FILE_PATH.
- EDT_LOGICAL_FILE_ALIAS, which uses the logical file path EDT_LOGICAL_FILE.
Reason and prerequisites
The programs contained in the correction instructions have vulnerabilities that allow a malicious user to potentially read arbitrary files on the remote server, possibly disclosing confidential information. Some of these programs also contain vulnerabilities that enable a malicious user to potentially write arbitrary files on the remote server, possibly corrupting data or altering system behavior.
References
This note refers to
Affected components
- SAP_ABA 620
- SAP_ABA 640
- SAP_ABA 700 to 702
- SAP_ABA 710 to 711
- SAP_ABA 730
Full note on SAP: SAP Support Launchpad note 1511552
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



