Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Directory traversal in MFG-MII, SAP security note 2230978

SAP Note 2230978
High priority

SAP security note 2230978, "Directory traversal in MFG-MII", released on February 18, 2016. Below are the symptom and SAP recommended solution.

ComponentSAP Manufacturing Integration and Intelligence (MFG-MII)
PriorityHigh priority
StatusReleased for Customer
Released onFebruary 18, 2016

Description

Symptom

A directory traversal vulnerability has been identified in SAP Manufacturing Integration and Intelligence (MFG-MII). The Catalog service can display file names from folders other than the one specified in the parameters. While users can only view the list of file names, they do not have the rights to access, modify, or delete the contents of these files.

Solution

  • Assign roles carefully: ensure that roles assigned to run the Catalog service are managed judiciously using the NetWeaver Administrator.
  • Implement the security note: apply the corrective measures provided in SAP Security Note 2230978.

Reason and prerequisites

An attacker could exploit this vulnerability to retrieve the names of files from unauthorized directories. While the attacker cannot access the contents or modify the files, the information gained can aid in further attacks or reconnaissance efforts.

CVSS

Score 4.0 Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Full note on SAP: SAP Support Launchpad note 2230978

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More