Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Directory traversal in ENGINEAPI, SAP security note 1779578

SAP Note 1779578
High priority

SAP security note 1779578, "Directory Traversal in ENGINEAPI", is a program error note released on May 14, 2013. Below are the symptom, SAP recommended solution and the affected software components.

CategoryProgram error
PriorityCorrection with high priority
StatusReleased for Customer
Released onMay 14, 2013

Description

Symptom

SAP has released Security Note 1779578 addressing a Directory Traversal vulnerability in ENGINEAPI. This issue allows an attacker to read arbitrary files on the remote server, potentially disclosing confidential information.

An attacker can exploit this vulnerability to access sensitive files on the server, leading to potential data breaches.

Solution

To mitigate this vulnerability, update your system to the latest support package levels as specified below:

CVSS

Score 5.0 Vector: AV:N/AC:L/AU:N/C:P/I:N/A:N

Affected components

  • ENGINEAPI – NW 7.10 – SP13 and higher
  • ENGINEAPI – NW 7.11 – SP08 and higher
  • ENGINEAPI – NW 7.20 – SP06 and higher
  • ENGINEAPI – NW 7.30 – SP04 and higher
  • ENGINEAPI – NW 7.31 – SP01 and higher

Full note on SAP: SAP Support Launchpad note 1779578

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More