SAP Security Note
High priority
SAP security note 1504016, "Directory Traversal in BC-DOC-DTL", is a program error note released on 11.01.2011. Below are the symptom and SAP recommended solution.
Description
Symptom
Component BC-DOC-DTL contains a vulnerability that allows a malicious user to potentially read arbitrary files on the remote server, possibly disclosing confidential information.
The same component allows a malicious user to potentially write arbitrary files on the remote server, possibly corrupting data or altering system behavior.
Solution
- Implement the corrections using the Note Assistant or import the relevant Support Package into your SAP system.
- After applying these corrections, the affected code is completely disabled.
Reason and prerequisites
BC-DOC-DTL fails to correctly validate the path used to reference files read from the remote server. This allows an attacker to point the program to any arbitrary file on the system, disclosing its contents.
It also fails to correctly validate the path where user-submitted files are written, enabling attackers to overwrite data on the remote system.
References
This note refers to
Full note on SAP: SAP Support Launchpad note 1504016
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
