SAP security note 1532325, "LO-MD-MM: Directory traversal vulnerability", is a note. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
The component LO-MD-MM contains a directory traversal vulnerability. Affected program: RMMMBIM0.
Solution
Implement the attached correction instructions provided in the note. For additional information and instructions, refer to Note 1497003. The corrections in Note 1497003 are a prerequisite for implementing this note.
- Logical file name: MATERIAL_MASTER_BTCI_LOG
- Program using logical file name: RMMMBIM0
- Logical file path: LO_MD_ROOT
Refer to Note 1498832 for additional information on setting up logical file names related to file name validation.
Reason and prerequisites
The program RMMMBIM0 has vulnerabilities that allow a malicious user to potentially read arbitrary files on the remote server, which may lead to the disclosure of confidential information.
CVSS
Score 0
References
This note refers to
Affected components
- SAP_APPL 31I to 605
Full note on SAP: SAP Support Launchpad note 1532325
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




