SAP Security Note
Medium priority
SAP security note 2318953, "Directory Traversal vulnerability in CO-PA-TO", is a program error note released on 15.03.2017. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
CO-PA-TO allows an attacker to exploit insufficient validation of path information provided by users, allowing characters that represent traversal to the parent directory to pass through to the file APIs.
Impacts of Directory Traversal vulnerability:
- Attacker could read the content of arbitrary files on the remote server, exposing sensitive data.
- Attacker could overwrite, delete, or corrupt arbitrary files on the remote server.
Solution
Implement the provided Support Package or follow the correction instructions detailed in this note.
CVSS
Score 0
References
This note refers to
Affected components
- SAP_APPL (600 to 616)
- SAP_FIN (617 to 730)
- S4CORE (100)
Full note on SAP: SAP Support Launchpad note 2318953
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




