SAP security note 1511612, “Directory Traversal Vulnerability in Hardware Information Display”, released on 14.03.2012. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
A directory traversal vulnerability exists in transaction ST06 and ST06N, allowing unauthorized reading of files accessible to the application server. This vulnerability arises because the function module used to display hardware configuration information does not properly restrict file access. Users with the appropriate authorizations can exploit this flaw to access arbitrary files on the system.
Solution
Implement the relevant correction instructions or import the appropriate Support Package based on your system’s component and version.
References
Affected components
- SAP_APPL: 31I to 45B
- SAP_BASIS: 46B to 730
Full note on SAP: SAP Support Launchpad note 1511612
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




