SAP Security Note
High priority
SAP security note 1597789, “IN86: Potential Directory Traversal”, is a program error note released on 08.11.2011. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
A potential Directory Traversal vulnerability exists in the component XX-CSC-BR-REP. This vulnerability allows a malicious user to write and delete arbitrary files on the remote server, potentially corrupting data or altering system behavior.
Affected Programs:
- J_1BLFC1
- J_1BLFC12
- J_1BLFC4
- J_1BLFC5
Solution
- Apply Note 1497003: Before implementing the corrections in this note, ensure that Note 1497003 is applied. This note provides additional information and instructions necessary for the proper implementation of the security measures.
Reason and prerequisites
Certain programs within the specified component contain a vulnerability that could be exploited to manipulate the file system on the server. Implementing the corrections from this note requires that Note 1497003 be applied as a prerequisite.
CVSS
Score 0
References
- 1699041 – IN86: Potential Directory Traversal
- 1497003 – Potential directory traversals in applications
Affected components
- SAP_APPL, versions 46C, 470, 500, 600, 602, 603, 604, 605
Full note on SAP: SAP Support Launchpad note 1597789
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
