SAP Security Note
Medium priority
SAP security note 1796761, “Directory traversal in CRM Handheld Service”, is a program error note released on 13.08.2013. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Read-write or write directory traversal:
CRM Handheld Service contains a vulnerability through which an attacker can potentially write arbitrary files to the remote server, possibly corrupting data or altering system behavior.
Solution
- Follow the manual instructions.
- Implement the attached correction instructions.
For more information, refer to SAP Note 1497003.
Reason and prerequisites
Read-write or write directory traversal:
CRM Handheld Service fails to correctly validate the path to which a user-submitted file is written. As a result, an attacker can potentially overwrite data in the remote system.
Affected components
- BBPCRM 500
- BBPCRM 600
- BBPCRM 700
- BBPCRM 701
- BBPCRM 702
- BBPCRM 712
- BBPCRM 713
Full note on SAP: SAP Support Launchpad note 1796761
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
