Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

FI-BL-PT-FO Possible directory traversal, SAP security note 1511617

SAP Note 1511617
SAP Security Note
High priority

SAP security note 1511617, "FI-BL-PT-FO: Possible directory traversal", is a program error note released on 12.01.2011. Below are the symptom, SAP recommended solution and the affected software components.

ComponentFinancial Accounting > Bank-Related Accounting > Payment Transactions > payment forms
CategoryProgram error
PriorityCorrection with high priority
TypeSAP Security Note
Version12
StatusReleased for Customer
Released on12.01.2011
LanguageEnglish

Description

Symptom

Component FI-BL-PT-FO: Potential directory traversal

This security note has been updated. For more information see security note 1538366.

Solution

See 1497003 for additional information on this issue. The corrections from Note 1497003 are a prerequisite for implementing this note.

Logical File Names: FI_DME_DOWNLOAD_PATH, FI_DME_DOWNLOAD_FILE (Programs: Transaction FDTA); FI_DME_CREATE_PATH, FI_DME_CREATE_FILE (Programs: SAPFPAYM, RFFOD__L, RFFOD__U, RFFOD__Z).

If you do not want to check the file name and path, you do not have to take any action. If you want to carry out a check, in transaction FILE, define an actual path or actual file name for the above logical file names and logical path names.

Note: If the check fails, no payment medium file is created either. If the check fails in transaction FDTA, the system issues an information message and the file is not downloaded.

After you implement the corrections from this note, implement the corrections from Note 1538366 also. The corrections do not contain the logical file names and paths.

Reason and prerequisites

1. The programs listed in the correction instructions contain a vulnerability that a malicious user could use to read any files, potentially containing confidential data, on a remote server.

2. Some of the programs listed in the correction instructions contain a vulnerability that a malicious user could use to overwrite any files on a remote server in order to potentially destroy data or to change the system response.

Side effects

Causes side effects in 1538366 – Update 1 to Security Note 1511617.

CVSS

Score 0

References

Affected components

  • SAP_APPL: 31I, 40B, 45B, 46B, 46C, 470, 500, 600, 602, 603, 604, 605

Full note on SAP: SAP Support Launchpad note 1511617

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More