High
SAP security note 1508060, "Directory Traversal in Billing Consolidation Connectors", was released on December 14, 2010. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
The Billing Consolidation Connector fails to correctly validate the path where user-submitted files are written. This vulnerability permits attackers to overwrite data on the remote system.
Solution
To mitigate this vulnerability, apply the relevant support packages or follow the correction instructions provided in SAP Note 1497003. Ensure that the prerequisites outlined in the correction instructions are met before implementation.
Affected components
- SAP_APPL 604
- SAP_APPL 605
Full note on SAP: SAP Support Launchpad note 1508060
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
