SAP security note 1502330, "Directory traversal in DUEVA download function of BaFin", is a note. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
SAP Security Note 1502330 addresses a directory traversal vulnerability in the DUEVA (DÜVA) download function used within the statutory reporting interface for BaFin (German Federal Financial Supervisory Authority). This vulnerability allows unauthorized reading or writing of data over the network, potentially compromising system integrity and data confidentiality.
Solution
To remediate this issue, apply the corrections outlined in SAP Security Note 1497003, as they are prerequisites for implementing this note effectively.
The following logical file names and paths have been created to validate physical file names and paths: FSSR_CL_EXM_IM_CONVERT_TO_TXTFILELT, FSSR_CL_IM_CONVERT_TO_DUVA_DE, FSSR_CL_ISSR_TOOLS, FSSR_CL_IM_CONVERT_TO_DUVA_FRONTEND.
Affected components
- FS-SR-DE
Full note on SAP: SAP Support Launchpad note 1502330
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
