High
SAP security note 1585924, "Directory Traversal Vulnerability in Legacy System Migration Workbench", is released on August 9, 2011. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Certain LSMW Function Modules and reports do not properly validate the path for user-submitted files, enabling attackers to overwrite data on the remote system.
Solution
Refer to SAP Note 1497003 for additional information and instructions. Implementing the corrections from Note 1497003 is a prerequisite for applying this note.
- Logical file names:
/SAPDMC/LSMW_FILE - Logical file paths:
/SAPDMC/LSMW_FILE_LP
Affected components
- SAP_BASIS 620 to 730
Full note on SAP: SAP Support Launchpad note 1585924
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
