SAP security note 1503884, “Directory Traversal in ISMW”, is a note released on 14.12.2010. Below is the security information published by SAP for this note.
Description
#### Symptom Potential Directory Traversal in Industry Solution Migration Workbench (ISMW).
#### Other Terms directory, traversal, ISMW, transaction EMIGALL
#### Reason and Prerequisites Read-write directory traversal contains a vulnerability through which a malicious user can potentially write arbitrary files on the remote server, possibly corrupting data or altering system behavior.
#### Solution Please refer to SAP Note 1497003 for additional information and instructions. The corrections from SAP Note 1497003 are a prerequisite for the implementation of this note.
Affected components
- IS-U/CCS: Versions 461, 464, 471
- FI-CA: Versions 472, 600, 602, 603, 604, 605
References
Full note on SAP: SAP Support Launchpad note 1503884
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



