SAP Security Note
High priority
SAP security note 1612092, "PSM: Potential Directory Traversal", is released on 13.09.2011. Below are the symptom and SAP recommended solution.
Description
Symptom
Potential Directory Traversal in the PSM component.
The program contained in the correction instructions has vulnerabilities that allow a malicious user to:
- Read arbitrary files on the remote server, potentially disclosing confidential information.
- Write arbitrary files on the remote server, possibly corrupting data or altering system behavior.
Solution
- Apply the corrections provided in this note.
- Ensure that Note 1497003 and Note 1605703 are implemented beforehand.
Reason and prerequisites
To implement this note, the corrections from Note 1497003 and Note 1605703 are prerequisites.
References
- 1605703: RSFILECR: Potential directory traversals in applications
- 1497003: Potential directory traversals in applications
Full note on SAP: SAP Support Launchpad note 1612092
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
