SAP security note 1582743, “Directory Traversal issue in CA-GTF-RCM”, is a note released on 08.11.2011. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
A vulnerability exists in CA-GTF-RCM where certain class methods and reports can be exploited by a malicious user to read arbitrary files on the remote server, potentially exposing confidential information.
Solution
Refer to SAP Note 1497003 for additional information and instructions. The corrections from this note are a prerequisite for implementing SAP Security Note 1582743.
Logical file name used: RMPS_IMPORT_PATH. Logical file path used: RMPS_TRF_IMPORT_DIR.
References
Affected components
- CA-GTF-RCM
- SAP_ABA 702
- SAP_ABA 730
Full note on SAP: SAP Support Launchpad note 1582743
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
