SAP security note 1517561, "Directory Traversal in ICM_READ_TRC_FILE2", is a note. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
The function module ICM_READ_TRC_FILE2 contains a vulnerability that allows a malicious user to perform directory traversal, potentially enabling the reading of arbitrary files and disclosing confidential information.
An attacker can exploit this vulnerability to access sensitive files on the system, leading to unauthorized disclosure of confidential data.
Solution
Implement the corrections specified in SAP Note 1517561.
Affected components
- SAP_BASIS: versions 700 to 800
Full note on SAP: SAP Support Launchpad note 1517561
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



