SAP security note 1509403, "Potential directory traversals in transaction TVDT", is a note released on August 16, 2011. Below are the symptom and SAP recommended solution.
Description
Symptom
Potential directory traversals in transactions TVDT using physical file names as input.
Solution
Refer to Note 1497003 for additional information and instructions. The corrections from Note 1497003 are a prerequisite for implementing this note.
Reason and prerequisites
The programs contained in the correction instructions have vulnerabilities that allow a malicious user to potentially read arbitrary files on the remote server, possibly disclosing confidential information.
Some programs contain vulnerabilities that allow a malicious user to potentially write arbitrary files on the remote server, possibly corrupting data or altering system behavior.
References
- 1509869 – Market Data Interface: Potential Directory Traversal
- 1497003 – Potential directory traversals in applications
Full note on SAP: SAP Support Launchpad note 1509403
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
