SAP security note 1521857, "RN2_MSI_ADT: Directory Traversal". Below are the symptom and SAP recommended solution.
Description
Symptom
Potential Directory Traversal in the following components:
- Program RN2_MSI_ADT
Solution
Please refer to Note 1497003 for additional information and instructions. The corrections from this note are a prerequisite for the implementation of this note.
Logical File Name Used in this Solution:
The following logical file name has been created to enable the validation of physical file names:
- ISHMED_RAD_MSI_FILE
Reason and prerequisites
The report contains a vulnerability through which a malicious user can potentially write arbitrary files on the remote server, possibly corrupting data or altering system behavior.
References
Full note on SAP: SAP Support Launchpad note 1521857
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
