SAP Security Note
High priority
SAP security note 1635445, "Directory Traversal in XX-PART-ISHMED", is a program error note released on 08.11.2011. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
XX-PART-ISHMED contains a vulnerability through which a malicious user can potentially write arbitrary files on the remote server, possibly disclosing confidential data.
Solution
The corrections are supplied with the specified patches. You can implement the attached correction instructions as an advance correction.
Reason and prerequisites
XX-PART-ISHMED fails to correctly validate the path that is used to reference a file that is read from the remote server. As a result, a malicious user can potentially direct the program to an arbitrary other file in the system, disclosing its content.
CVSS
Score 0
Affected components
- IS-H 463B
- IS-H 472
- IS-H 600
- IS-H 602
- IS-H 603
- IS-H 604
- IS-H 605
Full note on SAP: SAP Support Launchpad note 1635445
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
