SAP security note 1837735, "Directory traversal in component ICM", is a note. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
The ICM-MD component fails to properly validate the file path used to reference files read from the remote server. This oversight enables an attacker to manipulate the file path, directing the program to access unauthorized files within the system, thereby exposing their contents.
Solution
To mitigate this vulnerability, apply the corrections provided in SAP Note 1497003. Implementing the corrections from this note is a prerequisite for applying this security note.
References
- SAP Note 1511119 – ICM: Potential Directory Traversal
- SAP Note 1497003 – Potential directory traversals in applications
Affected components
- ICM-MD (Incentive and Commission Management > Basic and Master Data)
- EA-APPL 600 to 616
Full note on SAP: SAP Support Launchpad note 1837735
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
