Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Update 1 to SAP security note 1755108, SAP security note 1820777

SAP Note 1755108
SAP Security Note
HotNews

SAP security note 1755108, “Directory Traversal in Adminadapter Service”, is a program error note released on 08.01.2013. Below are the symptom and SAP recommended solution.

ComponentBasis Components > NetWeaver Application Server Java > Local Admin Tools > Administration
CategoryProgram error
PriorityHotNews
TypeSAP Security Note
Version5
StatusReleased for Customer
Released on08.01.2013

Description

Symptom

The adminadapter service contains vulnerabilities that allow an attacker to:

  • Read arbitrary files: Potentially disclosing confidential information.
  • Write arbitrary files: Possibly corrupting data or altering system behavior.
  • Escalate privileges: Authenticated users can access functions that should be restricted.

Solution

Apply the appropriate Patch Level for your version and service pack that includes all the fixes attached to this note. Please check the Validity section for detailed information on supported software components and corresponding patches.

Reason and prerequisites

The adminadapter service fails to correctly validate file paths, allowing attackers to:

  • Directory Traversal: Direct the program to arbitrary files, disclosing contents.
  • File Overwrite: Overwrite data in the remote system.
  • Lack of Authorization Checks: Access functions without proper authorization, leading to undesired system behavior.

CVSS

Score 10.0 Vector: AV:N/AC:L/AU:N/C:C/I:C/A:C

References

Full note on SAP: SAP Support Launchpad note 1755108

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More