Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

FI Potential Directory Traversal – China, SAP security note 1507789

SAP Note 1507789
SAP Security Note
High priority

SAP security note 1507789, "FI: Potential Directory Traversal – China", was released on December 14, 2010. Below are the symptom, SAP recommended solution and the affected software components.

ComponentMiscellaneous > Country/Region-Specific Developments > China
PriorityCorrection with high priority
TypeSAP Security Note
Version3
StatusReleased for Customer
Released onDecember 14, 2010

Description

Symptom

Potential Directory Traversal in the following components:

  • XX-CSC-CN

Solution

Please refer to SAP Note 1497003 for additional information and instructions. The corrections from note 1497003 are a prerequisite for the implementation of this note.

Logical file name used in this solution: FI_GACN_TXT_FILE_NAME, used by program RFCNGAIS and function module IDCN_GAIS_CREATE_FILE. Logical file path used in this solution: FI_GACN_FILE_PATH.

Reason and prerequisites

Some of the programs contained in the correction instructions contain a vulnerability through which a malicious user can potentially write arbitrary files on the remote server, possibly corrupting data or altering system behavior.

CVSS

Score 0

References

Affected components

  • SAP_APPL 46C
  • SAP_APPL 470
  • SAP_APPL 500
  • SAP_APPL 600
  • SAP_APPL 602
  • SAP_APPL 603
  • SAP_APPL 604
  • SAP_APPL 605

Full note on SAP: SAP Support Launchpad note 1507789

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More