SAP security note 1609678, “Directory Traversal in XX-PART-ISHMED-DOC”, is a program error note released on 08.11.2011. Below are the symptom and SAP recommended solution.
Description
Symptom
(read-write or write directory traversal) [COMPONENTNAME] contains a vulnerability through which a malicious user can potentially write arbitrary files on the remote server, possibly corrupting data or altering system behaviour.
Solution
The corrections are supplied with the specified patches. You can implement the attached correction instructions as an advance correction.
Reason and prerequisites
XX-PART-ISHMED fails to correctly validate the path that is used to reference a file that is read from the remote server. As a result, a malicious user can potentially direct the program to an arbitrary other file in the system, disclosing its contents.
CVSS
Score 0
References
Full note on SAP: SAP Support Launchpad note 1609678
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



