Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Directory traversal Old regulatory rptg in Austrian FMA, SAP security note 1501905

SAP Note 1501905
SAP Security Note
High priority

SAP security note 1501905, "Directory Traversal Vulnerability in Austrian FMA Reporting", is a program error note released on 14.12.2010. Below are the symptom, SAP recommended solution and the affected software components.

ComponentFS-SR-AT (Financial Services > Statutory Reporting for Insurancies > Austria)
CategoryProgram error
PriorityCorrection with high priority
TypeSAP Security Note
Version6
StatusReleased for Customer
Released on14.12.2010
LanguageEnglish (Master Language: German)

Description

Symptom

This SAP Security Note addresses a directory traversal vulnerability with write or read and write authorization in the download function of the old solution for the Financial Market Authority (FMA) notifications of regulatory reporting in Austria. The vulnerability allows an attacker to read or write any data using the network.

Solution

Refer to Note 1497003 for additional important information and instructions. The corrections in this note are a crucial prerequisite for implementing the fixes in Note 1501905.

Corrections implemented:

  • Created logical file names and paths to validate physical file names and paths.
  • Updated relevant programs and classes to utilize these logical names and parameters.

Reason and prerequisites

An error exists in the directory traversal mechanism when checking paths for data written by users in the old regulatory reporting solution for the Austrian FMA. This flaw can be exploited to transfer arbitrary data to the remote system or overwrite existing data.

References

Affected components

  • FS-SR-AT

Full note on SAP: SAP Support Launchpad note 1501905

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More