SAP security note 1543851, “Potential directory traversals in applications”, is a note. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Potential directory traversals in applications using physical file names or logical file names as input.
This note provides the additional correction instructions which need to be applied in case you decide not to import the transport request as described in Note 1497003. As mentioned in Note 1497003, SAP recommends that you import the transport request to avoid issues with copy & paste errors or other errors related to manual application or creation of corrections and objects.
Solution
- Complete the manual pre-implementation steps according to Note 1497003.
- Apply the correction instructions of Note 1543851.
- Complete the manual post-implementation steps according to Note 1497003.
Reason and prerequisites
Please refer to Note 1497003 for more details.
References
This note refers to
- Note 1677794 – Erstellung der Einlieferungsdaten für die Deutsche Post AG
- Note 1593845 – Clarification on implementation of Notes 1497003 and 1543851
- Note 1566528 – Directory traversal in IS-M
- Note 1542033 – Update #1 for security note 1497003
- Note 1497003 – Potential directory traversals in applications
Affected components
- Applicable to various releases of SAP_APPL and SAP_BASIS from 31I up to 730.
Full note on SAP: SAP Support Launchpad note 1543851
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
