Description
A security vulnerability exists in SAP B2B/B2C CRM that allows an attacker to read arbitrary local files from the affected server. The file initProductCatalog.do is affected and this vulnerability can be exploited via the GET parameter forwardPath.
Remediation
Upgrade SAP B2B/B2C CRM to the latest version.
Please consult the SAP Security Note 1870255656 for more information about the fix.
References
Related Vulnerabilities
WordPress Plugin Revamp CRM for WooCommerce Local File Inclusion (1.0.3)
WordPress Plugin WordPress Infinite Scroll-Ajax Load More Local File Inclusion (2.11.1)
WordPress Plugin Consulting Elementor Widgets Local File Inclusion (1.3.0)
WordPress Plugin myEASYbackup 'dwn_file' Parameter Directory Traversal (1.0.8.1)