Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Bank master data Potential Directory Traversal, SAP security note 1505512

SAP Note 1505512
SAP Security Note
High priority

SAP security note 1505512, “Bank master data: Potential Directory Traversal”, is a program error note released on 14.12.2010. Below are the symptom, reason and prerequisites, SAP recommended solution, references and the affected software components.

ComponentCross-Application Components > Bank (CA-BK)
CategoryProgram error
PriorityCorrection with high priority
TypeSAP Security Note
Version5
StatusReleased for Customer
Released on14.12.2010
LanguageEnglish

Description

Symptom

Potential Directory Traversal in the following programs (transactions):

  • RFBVALL_0 (BAUP)
  • RFBVBIC_0 (BIC)
  • RFBVBIC2 (BIC2)
  • RFIBANMD (IBANMD)

Solution

Please refer to Note 1497003 for additional information and instructions. The corrections from Note 1497003 are a prerequisite for implementing this note.

Logical File Names Used in this Solution:

  • BANK_DIRECTORY – used in program RFBVALL_0 for reading
  • BIC_PLUS_IBAN_DIRECTORY – used in programs RFBVBIC_0 and RFBVBIC2 for reading
  • IBAN_BIC_UPLOAD, IBAN_BIC_DOWNLOAD – used in program RFIBANMD for reading/uploading and writing/downloading.

Logical File Paths Used in this Solution:

  • BANK_DATA – used with logical file names BANK_DIRECTORY and BIC_PLUS_IBAN_DIRECTORY
  • IBAN_BIC_DATA – used with logical file names IBAN_BIC_UPLOAD and IBAN_BIC_DOWNLOAD

Reason and prerequisites

  • The programs contained in the correction instructions contain vulnerabilities that allow malicious users to potentially read arbitrary files on the remote server, possibly disclosing confidential information.
  • Some programs also allow malicious users to potentially write arbitrary files on the remote server, possibly corrupting data or altering system behavior.

References

Affected components

  • SAP_ABA (46C, 620, 640, 700 to 702, 710 to 711, 730)

Full note on SAP: SAP Support Launchpad note 1505512

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More