SAP Security Note
HotNews
SAP security note 1458309, "Directory Traversal in InfoView web portal", is a program error note released on October 12, 2010. Below are the symptom and SAP recommended solution.
Description
Symptom
A Business Objects Enterprise component installed with the Server components contains a vulnerability through which a malicious user can potentially write arbitrary files on the remote server, possibly corrupting data or altering system behavior by directing a user to a malicious site.
Solution
- XIr3 Customers: Apply Fixpack 2.7 or 3.1
- XIr2 Customers: Apply Fixpack 6.2
Customers without the fixpack can disable activeX access when using a web browser on the server machine.
CVSS
Score 0
Full note on SAP: SAP Support Launchpad note 1458309
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
