SAP security note 1507980, “Directory traversal in redemption schedule batch program”, is a note. Below are the symptom, SAP recommended solution, references and the affected software components.
Description
Symptom
SAP Security Note 1507980 addresses a directory traversal vulnerability in the redemption schedule batch program FTBAS_SCHEDULE_BATCH_LOAD. A malicious user could exploit this vulnerability to read arbitrary files on the remote server, potentially disclosing confidential information.
Solution
To mitigate this vulnerability, implement the correction instructions associated with this note or apply the relevant support packages.
Alternatively, refer to SAP Note 1497003 for more details on potential directory traversals in applications.
References
Affected components
- Transaction Manager (FIN-FSCM-TRM-TM) (110, 200, 500, 600, 603, 604, 605)
- BANK/CFM (463_20)
Full note on SAP: SAP Support Launchpad note 1507980
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
