Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Directory traversal in SV-SMG-MON-BPM, SAP security note 1863491

SAP Note 1863491
SAP Security Note
High priority

SAP security note 1863491, "Directory traversal in SV-SMG-MON-BPM", is a note released on October 8, 2013. Below are the symptom and SAP recommended solution.

ComponentService > SAP Solution Manager > Monitoring & Alerting > Business Process Operations (SV-SMG-MON-BPM)
PriorityHigh priority
TypeSAP Security Note
StatusReleased for Customer
Released onOctober 8, 2013

Description

Symptom

Component SV-SMG-MON-BPM contains a vulnerability that allows an attacker to perform directory traversal, potentially writing arbitrary files to the remote server. This could corrupt data or alter system behavior.

Solution

Apply this security note to disable the option to change the XML file path from the user interface.

Reason and prerequisites

SV-SMG-MON-BPM fails to correctly validate the path for user-submitted files, enabling attackers to overwrite data in the remote system.

Full note on SAP: SAP Support Launchpad note 1863491

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More