SAP security note 1512396, “Potential directory traversals in application N2UX”, is a note. Below is the security information published by SAP for this note.
Description
Symptom
Potential Directory Traversal vulnerability in transaction N2UX.
Reason and prerequisites
This vulnerability allows a malicious user to write or delete arbitrary files on the remote server, potentially corrupting data or altering system behavior.
Solution
Please refer to note 1497003 for additional information and instructions. The corrections from note 1497003 are a prerequisite for implementing this note.
A logical file N2UX_BASE has been created to validate physical file names. User-supplied file paths and filenames are validated against this logical filename.
References
- 1639118 – Note Number 1635447 Correction Directions for Patch 4
- 1635447 – Directory Traversal in XX-PART-ISHMED
- 1497003 – Potential directory traversals in applications
Full note on SAP: SAP Support Launchpad note 1512396
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
