Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Directory Traversal problem in the OCS functionality, SAP security note 1528292

SAP Note 1528292

SAP security note 1528292, “Directory Traversal problem in the OCS functionality”. Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

The OCS functionality (Support Package Manager or Add-On Installation Tool) contains a vulnerability through which a malicious user can potentially process arbitrary files on the remote server, possibly disclosing confidential information.

Solution

Basis Release 6.20 – 7.30: This error is fixed in the SPAM/SAINT update (Version 0040). Implement this SPAM/SAINT update (or a higher update) as soon as possible.

After implementing the update, users can read files and process via RFC only if they have system administrator authorization.

Basis Release 4.6x: This error is fixed in the SPAM/SAINT update (Version 4.6C/0051). Implement this SPAM/SAINT update (or a higher update) as soon as possible. You can also import the SPAM/SAINT update for Basis Release 4.6C in systems with Basis Releases 4.6B and 4.6D.

After implementing the update, users can read files and process via RFC only if they have system administrator authorization.

R/3 Releases 4.0B and 4.5B: Import the latest SPAM/SAINT update (Version 0049) and then implement the corrections of the following correction instructions.

After applying these corrections, users can read files and process via RFC only if they have system administrator authorization.

Reason and prerequisites

The OCS functionality fails to correctly validate the authorization of RFC-enabled function modules with which a file that is read and processed from the remote server is referenced. If a malicious user has knowledge of any user in the SAP system, they can open any file for processing via RFC.

Affected components

  • SAP_APPL: Releases 40B and 45B
  • SAP_BASIS: Releases 46B to 46D, 620 to 640, 700 to 702, 710 to 730

Full note on SAP: SAP Support Launchpad note 1528292

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More