High priority
SAP security note 2230978, "Directory traversal in MFG-MII", released on February 18, 2016. Below are the symptom and SAP recommended solution.
Description
Symptom
A directory traversal vulnerability has been identified in SAP Manufacturing Integration and Intelligence (MFG-MII). The Catalog service can display file names from folders other than the one specified in the parameters. While users can only view the list of file names, they do not have the rights to access, modify, or delete the contents of these files.
Solution
- Assign roles carefully: ensure that roles assigned to run the Catalog service are managed judiciously using the NetWeaver Administrator.
- Implement the security note: apply the corrective measures provided in SAP Security Note 2230978.
Reason and prerequisites
An attacker could exploit this vulnerability to retrieve the names of files from unauthorized directories. While the attacker cannot access the contents or modify the files, the information gained can aid in further attacks or reconnaissance efforts.
CVSS
Score 4.0 Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N
Full note on SAP: SAP Support Launchpad note 2230978
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
