Description
Read-only directory traversal
SAP Product and REACH Compliance contains a vulnerability through which a malicious user can potentially read arbitrary files on the remote server, possibly disclosing confidential information.
Read-write or write directory traversal
SAP Product and REACH Compliance contains a vulnerability through which a malicious user can potentially write arbitrary files on the remote server, possibly corrupting data or altering system behavior.
Available fix and Supported packages
- TDAGBCA | 110_500 | 110_500
- TDAGBCA | 110_600 | 110_600
- TDAGBCA | 200_500 | 200_500
- TDAGBCA | 200_600 | 200_600
- TDAGBCA 200_600 | SAPK-36002INTDAGBCA |
- TDAGBCA 200_500 | SAPK-35002INTDAGBCA |
- TDAGBCA 110_500 | SAPK-25005INTDAGBCA |
- TDAGBCA 110_600 | SAPK-26005INTDAGBCA |
Affected component
- EHS-SRC
SAP Product and REACH Compliance
CVSS
Score: 0
PoC
Detailed vulnerability information added to RedRays Security Platform. Contact [email protected] for details.
URL
https://launchpad.support.sap.com/#/notes/1513492