SAP Security Note
High priority
SAP security note 1504190, "PSM – Potential Directory Traversal", is a program error note released on December 14, 2010. Below are the symptom and SAP recommended solution.
Description
Symptom
SAP Security Note 1504190 addresses a potential directory traversal vulnerability in the Public Sector Management (PSM-FM) component. This issue allows a malicious user to potentially read or write arbitrary files on the remote server, which could lead to the disclosure of confidential information or corruption of data.
The vulnerability exists in the program contained within the correction instructions, which allows a malicious user to perform directory traversal attacks. Specifically:
- Read arbitrary files: Potentially disclose confidential information by reading arbitrary files on the server.
- Write arbitrary files: Potentially corrupt data or alter system behavior by writing arbitrary files on the server.
Solution
To address this vulnerability, refer to Note 1497003 for additional information and instructions. The corrections provided in Note 1497003 are prerequisites for the implementation of this note.
References
- 1497003 – Potential directory traversals in applications
- 1741394 – RFEXBLK0: Path descriptions are changed
Full note on SAP: SAP Support Launchpad note 1504190
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




