SAP security note 1509722, "Potential directory traversals in Creating Limits". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Potential directory traversals in the Batch Input Report for Creating Limits using physical file names as input.
Solution
Refer to SAP Note 1497003 for additional information and instructions. Implementing the corrections from SAP Note 1497003 is a prerequisite for applying SAP Note 1509722.
Logical file names used in this solution, in program RFTBLBI1 (Batch Input Report for Creating Limits):
- Logical file paths:
FTRM_AN_LIMIT(Treasury: Input file path for Limits),FTRM_AN_INT_LIMIT(Treasury: Input file path for Interim Limits) - Logical file names:
FTRM_AN_LIMIT(Treasury: Input file name for Limits),FTRM_AN_INT_LIMIT(Treasury: Input file name for Interim Limits)
Reason and prerequisites
- Read vulnerability: Malicious users can potentially read arbitrary files on the remote server, possibly exposing confidential information.
- Write vulnerability: Malicious users can potentially write arbitrary files on the remote server, which may corrupt data or alter system behavior.
References
This note refers to
Affected components
- EA-FINSERV: Versions 110, 200, 500, 600, 603, 604, 605
- BANK/CFM: Version 463_20
Full note on SAP: SAP Support Launchpad note 1509722
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
