Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Directory traversal possible, SAP security note 1499379

SAP Note 1499379
SAP Security Note
High priority

SAP security note 1499379, “Directory traversal possible”, is a program error note released on 14.12.2010. Below are the symptom and SAP recommended solution.

ComponentBasis Components > Upgrade – general
CategoryProgram error
PriorityCorrection with high priority
TypeSAP Security Note
Version5
StatusReleased for Customer
Released on14.12.2010
LanguageEnglish

Description

Symptom

Report RGTABKEY_COMPRESS and RGTABKEY_ROOT contain a vulnerability through which a malicious user can potentially write arbitrary files on the remote server, possibly corrupting data or altering system behavior.

Solution

Import the relevant Support Package or apply the correction instructions. The corrections do not have any influence on the normal functions of the application and no further adjustments or configurations are required, since these objects contain SAP-internal functionality.

Reason and prerequisites

Report RGTABKEY_COMPRESS and RGTABKEY_ROOT fail to correctly validate the path a user-submitted file is written to. Through this, an attacker can potentially overwrite data on the remote system.

Full note on SAP: SAP Support Launchpad note 1499379

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More