Skip links

Directory traversal in IS-OIL-PRA-REV-JE, SAP security note 1601530

Description

***********************************************************************WARNING: This is an IS-OIL / IS-MINE / IS-CWM specific note. If you DON’T have IS-OIL / IS-MINE / IS-CWM installed on your system, this note does not apply to you. If this note is applied and you do not have IS-OIL / IS-MINE / IS-CWM installed, you could cause serious damage to your system.
***********************************************************************

Potential directory traversal in the following components: IS-OIL-PRA-REV-JE (Load JEINTF).

Available fix and Supported packages

  • IS-OIL | 46C | 46C
  • IS-OIL | 472 | 472
  • IS-OIL | 600 | 600
  • IS-OIL | 602 | 602
  • IS-OIL | 603 | 603
  • IS-PRA | 604 | 604
  • IS-PRA | 605 | 605
  • IS-OIL 600 | SAPK-60020INISOIL |
  • IS-OIL 602 | SAPK-60210INISOIL |
  • IS-OIL 603 | SAPK-60309INISOIL |
  • IS-OIL 472 | SAPKI47061 |
  • IS-OIL 46C | SAPKI4C141 |
  • IS-PRA 604 | SAPK-60410INISPRA |
  • IS-PRA 605 | SAPK-60506INISPRA |

Affected component

    IS-OIL-PRA-REV
    Revenue

CVSS

Score: 0

Exploit

Detailed vulnerability information added to RedRays Security Platform. Contact [email protected] for details.

URL

https://launchpad.support.sap.com/#/notes/1601530

TAGS

#Directory-traversal
#IS-OIL-PRA-REV-JE
#Load-JEINTF-Report

How to detect over 4100 vulnerabilities in SAP Systems?

More to explorer

Initiating SAP Penetration Testing

►   Pentest, short for penetration testing, refers to a set of processes that simulate an attacker’s actions to identify security vulnerabilities. Companies

SAP Security Patch Day RedRays

May 2024 SAP Security Patch Day

Vulnerability: Multiple vulnerabilities in SAP CX Commerce SAP Component: CEC-SCC-PLA-PL CVE ID: CVE-2019-17495 CVSS Score: 9.8 CVSS Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Category: Program error