SAP security note 1598360, “MANAD: Potential Directory Traversal”, released on November 8, 2011. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Vulnerability: potential directory traversal in XX-CSC-BR-REP.
Affected programs:
- J_1BMANAD
- LJ1B_FI_EXTRACTF01
Solution
To remediate this vulnerability:
- Apply corrections from Note 1497003: these corrections are prerequisites for implementing Security Note 1598360.
- Implement the corrections following the detailed instructions provided in the correction instructions linked within the note.
Reason and prerequisites
Certain programs specified in the correction instructions contain a vulnerability that could allow a malicious user to write and delete arbitrary files on the remote server. Implementing this security note requires applying corrections from Note 1497003.
CVSS
Score 0
References
This note refers to
Affected components
- SAP_APPL (versions 46C to 605)
Full note on SAP: SAP Support Launchpad note 1598360
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
