Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Directory traversal in IS-H, central program part, SAP security note 1607749

SAP Note 1607749
High priority

SAP security note 1607749, "Directory traversal in IS-H, central program part", released on 18.11.2011. Below are the symptom and SAP recommended solution.

ComponentIS-H-CM (Industry-Specific Components > Hospital > Communication)
PriorityHigh priority
Version6
StatusReleased for Customer
Released on18.11.2011
LanguageEnglish (Master Language: German)

Description

Symptom

This security note addresses a potential directory traversal vulnerability in the following components:

  • IS-H-CM-OUT
  • IS-H-CM-INS

A malicious user could exploit this vulnerability to:

  • Read arbitrary files on the remote server, potentially disclosing confidential information.
  • Write arbitrary files on the remote server, possibly corrupting data or altering system behavior.

Solution

To resolve this issue, follow these steps:

1. Refer to Note 1497003. The corrections from this note are prerequisites for implementing this security note.

2. Set up logical file names for EDI procedures. Ensure that logical file names reflect the user and program names to securely separate data. Detailed instructions are provided within the note.

Reason and prerequisites

The vulnerability exists in the program parts specified in the correction instructions, which are prerequisites for correcting other programs with similar vulnerabilities.

References

Full note on SAP: SAP Support Launchpad note 1607749

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More