SAP security note 1511889, “Solving security issue in CPCC_DT_CREATE_SAMPLE_DATA”, is a program error note released on 14.12.2010. Below is the security information published by SAP for this note.
Description
Symptom
A subroutine present in the code potentially allows reading important files. This subroutine is not used by any piece of SAP code.
Reason and prerequisites
The report CPCC_DT_CREATE_SAMPLE_DATA contains a vulnerability through which a malicious user can potentially write arbitrary files on the remote server, possibly corrupting data or altering system behavior.
Solution
This subroutine must be removed to avoid possible external attacks. Apply this note for automatic correction.
References
Full note on SAP: SAP Support Launchpad note 1511889
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
