SAP Security Note
High priority
SAP security note 1507279, "FI: Potential Directory Traversal", is a program error note released on 14.12.2010. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Potential Directory Traversal in the following components: FBK.
Solution
Please refer to note 1497003 for additional information and instructions. The corrections from note 1497003 are a prerequisite for the implementation of this note.
Logical file name used in this solution: FI_RFKQSU40_FILE (program using this logical filename: RFKQSU40). Logical file path used in this solution: FI_FBK_FILE_PATH.
When setting up physical file paths, use the predefined parameter <PARAM_1> in the transaction FILE. Example physical path for syntax group UNIX: /usr/SAP/data/<SYSID>/<CLIENT>/<PARAM_1>/<Y=USER_NAME>/<FILENAME>, with the physical file name using data format DIR.
Reason and prerequisites
- The programs contained in the correction instructions have vulnerabilities that allow a malicious user to potentially read arbitrary files on the remote server, possibly disclosing confidential information.
- Some programs in the correction instructions have vulnerabilities that allow a malicious user to potentially write arbitrary files on the remote server, possibly corrupting data or altering system behavior.
CVSS
Score 0
References
This note refers to
Affected components
- SAP_APPL: Versions 31I, 40B, 45B, 46B, 46C, 470, 500, 600, 602, 603, 604, 605
Full note on SAP: SAP Support Launchpad note 1507279
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
