Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Directory traversal in ABAP Runtime Analysis, SAP security note 1913388

SAP Note 1913388

SAP security note 1913388, "Directory traversal in ABAP Runtime Analysis", is a security note. Below are the symptom and SAP recommended solution.

Description

Symptom

ABAP Runtime Analysis contains a vulnerability through which an attacker can potentially write arbitrary files to the remote server, possibly corrupting data or altering system behavior.

Solution

The programs specified in the correction instructions will not accept full path names, but only the file name after the correction. Please apply the support package mentioned in this note or the respective correction instructions.

Reason and prerequisites

ABAP Runtime Analysis fails to correctly validate the path to which a user-submitted file is written. As a result, an attacker can potentially overwrite data in the remote system.

Full note on SAP: SAP Support Launchpad note 1913388

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More