SAP Security Note
High priority
SAP security note 1506843, "FI: Potential Directory Traversal", is a program error note released on September 2, 2011. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
There is a potential Directory Traversal vulnerability in the FI-AP-AP-B1 component. This vulnerability allows a malicious user to read arbitrary files on the remote server, potentially disclosing confidential information. Additionally, some programs may allow writing arbitrary files, which could corrupt data or alter system behavior.
Solution
Logical file names have been created to validate physical file names:
- FI_RFEBFILUM00_FILE
- FI_RFIDATEB00_FILE
- FI_RFEBBE00_FILE
- FI_RFEBBE00_NACC_FILE
- FI_RFEBBECODA00_FILE
- FI_RFEBNO00_FILE
- FI_RFESR000_FILE
Logical File Paths Used:
- FI_FBZ_FILE_PATH
- FI_FTE_FILE_PATH
- FI_FBAS_FILE_PATH
Reason and prerequisites
- Programs within the correction instructions contain vulnerabilities for reading arbitrary files.
- Some programs allow writing arbitrary files on the remote server.
References
This note refers to
Referenced by
Affected components
- SAP_APPL, versions 31I to 605
- SAP_BASIS, versions 46B to 710
Full note on SAP: SAP Support Launchpad note 1506843
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
