Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Directory Traversal in MaxDB CCMS, SAP security note 1516432

SAP Note 1516432
SAP Security Note
High priority

SAP security note 1516432, "Directory Traversal in MaxDB CCMS", is a note released on 14.12.2010. Below are the symptom, SAP recommended solution and the affected software components.

ComponentBasis Components > Database Interface, Database Platforms > MaxDB
PriorityCorrection with high priority
TypeSAP Security Note
StatusReleased for Customer
Released on14.12.2010

Description

Symptom

The MaxDB CCMS contains a security gap that enables a malicious user to read all files with the file name extension .trc on the database host and disclose confidential information under certain circumstances.

Solution

Perform an upgrade to the following SAP NetWeaver Support Packages:

  • SAP NetWeaver 7.00 Support Package 23
  • SAP NetWeaver 7.01 Support Package 08
  • SAP NetWeaver 7.02 Support Package 06
  • SAP NetWeaver 7.10 Support Package 12
  • SAP NetWeaver 7.11 Support Package 06
  • SAP NetWeaver 7.20 Support Package 04
  • SAP NetWeaver 7.30 Support Package 02

Other SAP NetWeaver versions except for the ones listed above are not affected.

Until the upgrade is performed, ensure that only database administrators have access to the MaxDB CCMS.

Reason and prerequisites

The MaxDB CCMS fails to limit the read access to files with the file name extension .trc to the valid path. The malicious user must have authorizations to execute the CCMS and may read all files with the file name extension .trc on the database server and disclose their contents.

Affected components

  • SAP_BASIS: Versions 700 to 702, 710 to 730

Full note on SAP: SAP Support Launchpad note 1516432

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More