SAP security note 1517472, "FI-GL-IS: Potential Directory Traversal", is a program error note released on 14.12.2010. Below are the symptom and SAP recommended solution.
Description
Symptom
Potential Directory Traversal in the following components:
- FI-GL-IS
Solution
Please refer to Note 1497003 for additional information and instructions. The corrections from Note 1497003 are a prerequisite for the implementation of this note.
Logical File Names Used in this Solution:
- FI_EXTERNAL – Programs and Parameters:
- RFAWVZ58: Program name (SY-REPID), String 'AWV', Parameter 'Key Date'
- RFAWVZ5A: Program name (SY-REPID), String 'AWV', Parameter 'Key Date'
- (Additional programs listed in the detailed description)
- FI_POSTING – Programs and Parameters:
- RFBIBLT0: Program name (SY-REPID)
- RFEBCK00: Program name (SY-REPID), Parameter 'Document Type', Parameter 'Session name'
- (Additional programs listed in the detailed description)
- FI_TAX – Programs and Parameters:
- RFASLD02: Program name (SY-CPROG), Parameter year for 'Reporting quarter', Parameter 'Reporting quarter'
- (Additional programs listed in the detailed description)
Recommendations for Setup of Logical File Names: Please refer to Note 1498832 for additional information regarding the setup of logical file names in the context of file name validation.
Reason and prerequisites
- The programs contained in the correction instructions contain vulnerabilities through which a malicious user can potentially read arbitrary files on the remote server, possibly disclosing confidential information.
- Some of the programs contained in the correction instructions contain a vulnerability through which a malicious user can potentially write arbitrary files on the remote server, possibly corrupting data or altering system behavior.
CVSS
Score 0
References
- Note 1533776 – FI: Potential Directory Traversal
- Note 1498832 – FI: Potential Directory Traversal
- Note 1497003 – Potential directory traversals in applications
Full note on SAP: SAP Support Launchpad note 1517472
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
