Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Argentina J1ACAE Potential Directory Traversal, SAP security note 1533500

SAP Note 1533500

SAP security note 1533500, "Argentina J1ACAE: Potential Directory Traversal". Below are the symptom and the SAP recommended solution.

Description

Symptom

Potential Directory Traversal for J_1A_CAE.

Solution

Please refer to Note 1497003 for additional information and instructions. The corrections from Note 1497003 are a prerequisite for the implementation of this note.

The following logical file name has been created to enable the validation of physical file names: FI_J1ACAE_FILE, used by program J_1A_CAE. The application J_1A_CAE passes an additional parameter <PARAM_1> (program name, sy-cprog) to the function module FILE_VALIDATE_NAME. This allows a customer to insert the parameter while configuring the physical paths for the logical file name FI_J1ACAE_FILE. Logical file path used in this solution: FI_AEI_FILE_PATH.

Reason and prerequisites

The program contained in the correction instructions has vulnerabilities that allow a malicious user to potentially read or write arbitrary files on the remote server, possibly disclosing, corrupting, or altering confidential information.

References

Full note on SAP: SAP Support Launchpad note 1533500

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More