SAP Security Note
HotNews
SAP security note 1755108, “Directory Traversal in Adminadapter Service”, is a program error note released on 08.01.2013. Below are the symptom and SAP recommended solution.
Description
Symptom
The adminadapter service contains vulnerabilities that allow an attacker to:
- Read arbitrary files: Potentially disclosing confidential information.
- Write arbitrary files: Possibly corrupting data or altering system behavior.
- Escalate privileges: Authenticated users can access functions that should be restricted.
Solution
Apply the appropriate Patch Level for your version and service pack that includes all the fixes attached to this note. Please check the Validity section for detailed information on supported software components and corresponding patches.
Reason and prerequisites
The adminadapter service fails to correctly validate file paths, allowing attackers to:
- Directory Traversal: Direct the program to arbitrary files, disclosing contents.
- File Overwrite: Overwrite data in the remote system.
- Lack of Authorization Checks: Access functions without proper authorization, leading to undesired system behavior.
CVSS
Score 10.0 Vector: AV:N/AC:L/AU:N/C:C/I:C/A:C
References
Full note on SAP: SAP Support Launchpad note 1755108
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
