SAP security note 1510372, "FS-CD Potential Directory Traversal". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
A potential Directory Traversal vulnerability has been identified in the FS-CD component. This vulnerability allows a malicious user to potentially write arbitrary files on the remote server, which could lead to data corruption or alteration of system behavior.
Solution
Refer to Note 1497003 for additional information and instructions. Implementing the corrections from Note 1497003 is a prerequisite for applying this note.
Affected components
- INSURANCE (Versions 464, 471, 472, 600, 602, 603, 604, 605)
Full note on SAP: SAP Support Launchpad note 1510372
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
