Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Potential directory traversals using report RLMG0020, SAP security note 1510795

SAP Note 1510795

SAP security note 1510795, "Potential Directory Traversals Using Report RLMG0020", is a note. Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

Potential Directory Traversal in the following component:

  • LE-WM

Solution

Implement the correction instructions.

Please refer to Note 1497003 for additional information and instructions. The corrections from Note 1497003 are a prerequisite for the implementation of this note.

The following logical file name has been created in order to enable the validation of physical file names: WM_MATERIAL_MASTER_MLGN. The program RLMG0020 uses this logical file name.

The logical file name above uses the logical file path WM_ROOT.

Reason and prerequisites

The program contained in the correction instructions contains a vulnerability through which a malicious user can potentially write arbitrary files on the remote server, possibly corrupting data or altering system behavior.

References

Affected components

  • SAP_APPL from version 31I to 605

Full note on SAP: SAP Support Launchpad note 1510795

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More