• Все разделы
  • Статьи
  • Медиа
  • Новости
  • Нормативные материалы
  • Конференции
  • Глоссарий

Note 1755108 - Directory traversal in adminadapter service

Главная Специалистам База уязвимостей Note 1755108 - Directory traversal in adminadapter service

Карточка уязвимости

Характеристики уязвимости

Уровень опасности
Оценка CVSS
(AV:N/AC:L/AU:N/C:C/I:C/A:CSAP)
Производитель ПО
SAP
Наименование ПО
SAP Notes (1755108-5) SAP Support Packages (J2EE_ENGINE_SERVERCORE_710_SP012_000025, J2EE_ENGINE_SERVERCORE_710_SP013_000016, J2EE_ENGINE_SERVERCORE_710_SP014_000019, J2EE_ENGINE_SERVERCORE_710_SP015_000002, J2EE_ENGINE_SERVERCORE_710_SP016_000000, J2EE_ENGINE_SERVERCORE_710_SP999999_999999, J2EE_ENGINE_SERVERCORE_711_SP007_000025, J2EE_ENGINE_SERVERCORE_711_SP008_000021, J2EE_ENGINE_SERVERCORE_711_SP009_000021, J2EE_ENGINE_SERVERCORE_711_SP010_000003, J2EE_ENGINE_SERVERCORE_711_SP011_000000, J2EE_ENGINE_SERVERCORE_711_SP999999_999999, J2EE_ENGINE_SERVERCORE_720_SP005_000040, J2EE_ENGINE_SERVERCORE_720_SP006_000029, J2EE_ENGINE_SERVERCORE_720_SP007_000024, J2EE_ENGINE_SERVERCORE_720_SP008_000002, J2EE_ENGINE_SERVERCORE_720_SP009_000000, J2EE_ENGINE_SERVERCORE_720_SP999999_999999, J2EE_ENGINE_SERVERCORE_730_SP002_000030, J2EE_ENGINE_SERVERCORE_730_SP003_000030, J2EE_ENGINE_SERVERCORE_730_SP004_000026, J2EE_ENGINE_SERVERCORE_730_SP005_000039, J2EE_ENGINE_SERVERCORE_730_SP007_000023, J2EE_ENGINE_SERVERCORE_730_SP008_000000, J2EE_ENGINE_SERVERCORE_730_SP009_000000, J2EE_ENGINE_SERVERCORE_730_SP999999_999999, J2EE_ENGINE_SERVERCORE_731_SP002_000024, J2EE_ENGINE_SERVERCORE_731_SP003_000018, J2EE_ENGINE_SERVERCORE_731_SP004_000011, J2EE_ENGINE_SERVERCORE_731_SP005_000000, J2EE_ENGINE_SERVERCORE_731_SP006_000000, J2EE_ENGINE_SERVERCORE_731_SP999999_999999, SAP_J2EE_ENGINE_640_SP028_000017, SAP_J2EE_ENGINE_640_SP029_000011, SAP_J2EE_ENGINE_640_SP030_000003, SAP_J2EE_ENGINE_640_SP031_000000, SAP_J2EE_ENGINE_640_SP999999_999999, SAP_J2EE_ENGINE_CORE_640_SP031_000000, SAP_J2EE_ENGINE_CORE_640_SP999999_999999, SAP_J2EE_ENGINE_CORE_700_SP024_000019, SAP_J2EE_ENGINE_CORE_700_SP025_000017, SAP_J2EE_ENGINE_CORE_700_SP026_000015, SAP_J2EE_ENGINE_CORE_700_SP027_000004, SAP_J2EE_ENGINE_CORE_700_SP028_000000, SAP_J2EE_ENGINE_CORE_700_SP999999_999999, SAP_J2EE_ENGINE_CORE_701_SP009_000021, SAP_J2EE_ENGINE_CORE_701_SP010_000020, SAP_J2EE_ENGINE_CORE_701_SP011_000016, SAP_J2EE_ENGINE_CORE_701_SP012_000005, SAP_J2EE_ENGINE_CORE_701_SP013_000000, SAP_J2EE_ENGINE_CORE_701_SP999999_999999, SAP_J2EE_ENGINE_CORE_702_SP007_000023, SAP_J2EE_ENGINE_CORE_702_SP008_000022, SAP_J2EE_ENGINE_CORE_702_SP009_000021, SAP_J2EE_ENGINE_CORE_702_SP010_000017, SAP_J2EE_ENGINE_CORE_702_SP011_000020, SAP_J2EE_ENGINE_CORE_702_SP012_000002, SAP_J2EE_ENGINE_CORE_702_SP013_000000, SAP_J2EE_ENGINE_CORE_702_SP999999_999999)
Описание
The adminadapter service fails to correctly validate the path that is  used for referring a file that is read from the remote server. As a  result, an attacker can potentially direct the program to another arbitrary file in the system, disclosing its contents.The adminadapter service fails to correctly validate the path to which a  user-submitted file is written. As a result, an attacker can potentially overwrite data in the remote system.Additionally, the adminadapter service does not contain authorization  checks for checking the authenticated user's authorization in order to  access some of its functions. This may result in undesired system behavior.
Как исправить
Apply Patch Level for your version and service pack that contains all the fixes attached to this note. For details, check validity section.
Ссылки