High priority
SAP security note 1741239, "Directory Traversal in Web Dynpro ABAP", is a note released on May 14, 2013. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Web Dynpro ABAP contains a vulnerability that allows an attacker to write arbitrary files to the remote server, potentially corrupting data or altering system behavior.
Solution
Apply the correction instructions provided in SAP Security Note 1741239 or install the necessary service packs.
CVSS
Score 7.5 Vector: AV:N/AC:L/AU:N/C:P/I:P/A:P
Affected components
- SAP_BASIS 6.40 to 7.31
- SAP_BASIS 7.70 to 7.31
- SAP_BASIS 8.02 to 8.04
Full note on SAP: SAP Support Launchpad note 1741239
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
