High priority
SAP security note 1779578, "Directory Traversal in ENGINEAPI", is a program error note released on May 14, 2013. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
SAP has released Security Note 1779578 addressing a Directory Traversal vulnerability in ENGINEAPI. This issue allows an attacker to read arbitrary files on the remote server, potentially disclosing confidential information.
An attacker can exploit this vulnerability to access sensitive files on the server, leading to potential data breaches.
Solution
To mitigate this vulnerability, update your system to the latest support package levels as specified below:
- NW 7.10: SP13 and higher
- NW 7.11: SP08 and higher
- NW 7.20: SP06 and higher
- NW 7.30: SP04 and higher
- NW 7.31: SP01 and higher
CVSS
Score 5.0 Vector: AV:N/AC:L/AU:N/C:P/I:N/A:N
Affected components
- ENGINEAPI – NW 7.10 – SP13 and higher
- ENGINEAPI – NW 7.11 – SP08 and higher
- ENGINEAPI – NW 7.20 – SP06 and higher
- ENGINEAPI – NW 7.30 – SP04 and higher
- ENGINEAPI – NW 7.31 – SP01 and higher
Full note on SAP: SAP Support Launchpad note 1779578
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



