SAP Security Note
High priority
SAP security note 1598417, “DIRF: Potential Directory Traversal”, released on 08.11.2011. Below are the symptom and SAP recommended solution.
Description
Symptom
Potential directory traversal in XX-CSC-BR-REP.
Solution
Please refer to SAP Note 1497003 for additional information and instructions. The corrections from note 1497003 are a prerequisite to implement this note.
Reason and prerequisites
Some of the programs specified in the correction instructions contain a vulnerability through which a malicious user can potentially write and delete arbitrary files on the remote server, possibly corrupting data or altering system behavior.
References
This note refers to
Full note on SAP: SAP Support Launchpad note 1598417
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



