Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Directory traversal in DUEVA download function of BaFin, SAP security note 1502330

SAP Note 1502330

SAP security note 1502330, "Directory traversal in DUEVA download function of BaFin", is a note. Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

SAP Security Note 1502330 addresses a directory traversal vulnerability in the DUEVA (DÜVA) download function used within the statutory reporting interface for BaFin (German Federal Financial Supervisory Authority). This vulnerability allows unauthorized reading or writing of data over the network, potentially compromising system integrity and data confidentiality.

Solution

To remediate this issue, apply the corrections outlined in SAP Security Note 1497003, as they are prerequisites for implementing this note effectively.

The following logical file names and paths have been created to validate physical file names and paths: FSSR_CL_EXM_IM_CONVERT_TO_TXTFILELT, FSSR_CL_IM_CONVERT_TO_DUVA_DE, FSSR_CL_ISSR_TOOLS, FSSR_CL_IM_CONVERT_TO_DUVA_FRONTEND.

Affected components

  • FS-SR-DE

Full note on SAP: SAP Support Launchpad note 1502330

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More