SAP Security Note
High priority
SAP security note 1597158, “FI – Potential Directory Traversal in Venezuela”, is a security note released on 08.11.2011. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Potential Directory Traversal for RFVEPBOOK.
Solution
Please refer to Note 1497003 for additional information and instructions. The corrections from Note 1497003 are a prerequisite for the implementation of this note.
Reason and prerequisites
The programs contained in the correction instructions contain vulnerabilities that allow a malicious user to potentially read arbitrary files on the remote server, possibly disclosing confidential information. Some programs may allow a malicious user to write arbitrary files on the remote server, potentially corrupting data or altering system behavior.
References
This note refers to
Referenced by
Affected components
- SAP_APPL, versions 46C, 470, 500, 600, 602, 603, 604, 605
Full note on SAP: SAP Support Launchpad note 1597158
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
