SAP Security Note
SAP security note 1874456, "Directory traversal in CRM-BF-IIA", released on August 13, 2013. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
CRM-BF-IIA contains a vulnerability that allows an attacker to perform directory traversal. This can potentially enable the attacker to read arbitrary files on the remote server, leading to the disclosure of confidential information.
Solution
Refer to SAP Note 1497003 for additional information and instructions. Corrections from that note are a prerequisite for implementing this note.
CVSS
Score 0
References
Affected components
- Customer Relationship Management > Basic Functions > Interactive Intelligent Agent (CRM-BF-IIA)
- Customer Relationship Management > Interaction Center WebClient > Knowledge Search (CRM-IC-SOL)
Full note on SAP: SAP Support Launchpad note 1874456
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



