SAP Security Note
High priority
SAP security note 1516432, "Directory Traversal in MaxDB CCMS", is a note released on 14.12.2010. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
The MaxDB CCMS contains a security gap that enables a malicious user to read all files with the file name extension .trc on the database host and disclose confidential information under certain circumstances.
Solution
Perform an upgrade to the following SAP NetWeaver Support Packages:
- SAP NetWeaver 7.00 Support Package 23
- SAP NetWeaver 7.01 Support Package 08
- SAP NetWeaver 7.02 Support Package 06
- SAP NetWeaver 7.10 Support Package 12
- SAP NetWeaver 7.11 Support Package 06
- SAP NetWeaver 7.20 Support Package 04
- SAP NetWeaver 7.30 Support Package 02
Other SAP NetWeaver versions except for the ones listed above are not affected.
Until the upgrade is performed, ensure that only database administrators have access to the MaxDB CCMS.
Reason and prerequisites
The MaxDB CCMS fails to limit the read access to files with the file name extension .trc to the valid path. The malicious user must have authorizations to execute the CCMS and may read all files with the file name extension .trc on the database server and disclose their contents.
Affected components
- SAP_BASIS: Versions 700 to 702, 710 to 730
Full note on SAP: SAP Support Launchpad note 1516432
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



