Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Directory traversal in Condition tool, SAP security note 1531752

SAP Note 1531752
SAP Security Note
High priority

SAP security note 1531752, "Directory traversal in Condition tool", released on 08.03.2011. Below are the symptom and SAP recommended solution.

ComponentFinancial Services > Bank Analyzer > Tools > Module Editor
PriorityCorrection with high priority
TypeSAP Security Note
Version4
StatusReleased for Customer
Released on08.03.2011

Description

Symptom

The Condition tool contains a vulnerability that allows a malicious user to potentially write arbitrary files on the remote server. This can lead to data corruption or alteration of system behavior.

Solution

Implement the provided correction or the corresponding support package.

Reason and prerequisites

The Condition tool does not correctly validate the path where a user-submitted file is written. As a result, an attacker can overwrite condition data on the remote system.

CVSS

Score 0

Full note on SAP: SAP Support Launchpad note 1531752

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More