Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Directory Traversal in InfoView web portal, SAP security note 1458309

SAP Note 1458309
SAP Security Note
HotNews

SAP security note 1458309, "Directory Traversal in InfoView web portal", is a program error note released on October 12, 2010. Below are the symptom and SAP recommended solution.

ComponentBusiness intelligence solutions > Business intelligence platform > SAP Crystal Server (BI-BIP-CRS)
CategoryProgram error
PriorityHotNews
TypeSAP Security Note
StatusReleased for Customer
Released onOctober 12, 2010
LanguageEnglish

Description

Symptom

A Business Objects Enterprise component installed with the Server components contains a vulnerability through which a malicious user can potentially write arbitrary files on the remote server, possibly corrupting data or altering system behavior by directing a user to a malicious site.

Solution

  • XIr3 Customers: Apply Fixpack 2.7 or 3.1
  • XIr2 Customers: Apply Fixpack 6.2

Customers without the fixpack can disable activeX access when using a web browser on the server machine.

CVSS

Score 0

Full note on SAP: SAP Support Launchpad note 1458309

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More