Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

FI Potential Directory Traversal, SAP security note 1507279

SAP Note 1507279
SAP Security Note
High priority

SAP security note 1507279, "FI: Potential Directory Traversal", is a program error note released on 14.12.2010. Below are the symptom, SAP recommended solution and the affected software components.

ComponentFinancial Accounting > Accounts Payable > Basic Functions > Withholding Tax (Reporting)
CategoryProgram error
PriorityHigh priority
TypeSAP Security Note
Version2
StatusReleased for Customer
Released on14.12.2010
LanguageEnglish

Description

Symptom

Potential Directory Traversal in the following components: FBK.

Solution

Please refer to note 1497003 for additional information and instructions. The corrections from note 1497003 are a prerequisite for the implementation of this note.

Logical file name used in this solution: FI_RFKQSU40_FILE (program using this logical filename: RFKQSU40). Logical file path used in this solution: FI_FBK_FILE_PATH.

When setting up physical file paths, use the predefined parameter <PARAM_1> in the transaction FILE. Example physical path for syntax group UNIX: /usr/SAP/data/<SYSID>/<CLIENT>/<PARAM_1>/<Y=USER_NAME>/<FILENAME>, with the physical file name using data format DIR.

Reason and prerequisites

  • The programs contained in the correction instructions have vulnerabilities that allow a malicious user to potentially read arbitrary files on the remote server, possibly disclosing confidential information.
  • Some programs in the correction instructions have vulnerabilities that allow a malicious user to potentially write arbitrary files on the remote server, possibly corrupting data or altering system behavior.

CVSS

Score 0

References

Affected components

  • SAP_APPL: Versions 31I, 40B, 45B, 46B, 46C, 470, 500, 600, 602, 603, 604, 605

Full note on SAP: SAP Support Launchpad note 1507279

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More