Description
SAP Portal fails to correctly validate the path with which a file that is read from the remote server is referenced. Through this, an attacker can potentially point the program to an arbitrary other file on the system, disclosing its contents.
Remediation
Install SAP security note 1630293.
References
Related Vulnerabilities
WordPress Plugin WP-Lister Lite for Amazon Directory Traversal (0.9.6.35)
WordPress Plugin myEASYbackup 'dwn_file' Parameter Directory Traversal (1.0.8.1)
WordPress Plugin Live Scores for SportsPress Multiple Vulnerabilities (1.9.0)
WordPress Plugin WP-Lytebox 'pg' Parameter Local File Inclusion (1.3)