SAP security note 1581165, “Directory Traversal in BC-SRV-KPR”. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
SAP Security Note 1581165 addresses a directory traversal vulnerability in the BC-SRV-KPR component. This vulnerability allows a malicious user to write arbitrary files on the remote server, potentially leading to data corruption or altering system behavior.
Exploiting this vulnerability can enable attackers to overwrite data on the remote system, compromising the integrity and availability of the affected SAP environment.
Solution
To mitigate this vulnerability, implement the corrections provided in SAP Note 1581165 or import the relevant support packages.
Affected components
- SAP_BASIS: 620 to 640
- SAP_BASIS: 700 to 702
- SAP_BASIS: 710 to 730
- SAP_BASIS: 731
- SAP_BASIS: 802
Full note on SAP: SAP Support Launchpad note 1581165
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
