SAP security note 1502295, "Directory Traversal in BC-SRV-KPR-CMS". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
BC-SRV-KPR-CMS contains a vulnerability through which a malicious user can potentially write arbitrary files on the remote server, possibly corrupting data or altering system behavior.
Solution
To obtain this code change, please implement this note or import the relevant support package.
Reason and prerequisites
BC-SRV-KPR-CMS fails to correctly validate the path a user-submitted file is written to. Through this, an attacker can potentially overwrite data on the remote system.
Prerequisites:
References
- SAP Note 1522787: Directory Traversal in BC-SRV-KPR-CMS
- SAP Note 1497003: Potential directory traversals in applications
Affected components
- SAP_BASIS: versions 46C, 620, 640, 700, 701, 702, 710, 711, 720, 730
Full note on SAP: SAP Support Launchpad note 1502295
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



