SAP Security Note
High priority
SAP security note 1533533, "FI: Potential Directory Traversal- Belgium and France", was released on 04.12.2014. Below are the symptom and SAP recommended solution.
Description
Symptom
The programs contained in the correction instructions have vulnerabilities that allow a malicious user to potentially read or write arbitrary files on the remote server. This could lead to disclosing confidential information or corrupting data.
Solution
Please refer to SAP Note 1497003 for additional information and instructions. The corrections from note 1497003 are a prerequisite for implementing this note.
Reason and prerequisites
The vulnerabilities exist in the programs provided within the correction instructions. A malicious user exploiting these vulnerabilities can read or write arbitrary files on the remote server, which may result in the disclosure of confidential information or data corruption.
References
- SAP Note 2101271 – Update 1 to security note 1533533
- SAP Note 1497003 – Potential directory traversals in applications
Full note on SAP: SAP Support Launchpad note 1533533
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



