Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Directory Traversal vulnerability in CO-PA-TO, SAP security note 2318953

SAP Note 2318953
SAP Security Note
Medium priority

SAP security note 2318953, "Directory Traversal vulnerability in CO-PA-TO", is a program error note released on 15.03.2017. Below are the symptom, SAP recommended solution and the affected software components.

ComponentControlling > Profitability Analysis > Tools (CO-PA-TO)
CategoryProgram error
PriorityCorrection with medium priority
TypeSAP Security Note
Version1
StatusReleased for Customer
Released on15.03.2017
LanguageEnglish

Description

Symptom

CO-PA-TO allows an attacker to exploit insufficient validation of path information provided by users, allowing characters that represent traversal to the parent directory to pass through to the file APIs.

Impacts of Directory Traversal vulnerability:

  • Attacker could read the content of arbitrary files on the remote server, exposing sensitive data.
  • Attacker could overwrite, delete, or corrupt arbitrary files on the remote server.

Solution

Implement the provided Support Package or follow the correction instructions detailed in this note.

CVSS

Score 0

References

Affected components

  • SAP_APPL (600 to 616)
  • SAP_FIN (617 to 730)
  • S4CORE (100)

Full note on SAP: SAP Support Launchpad note 2318953

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More