Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Possible directory traversal (1105) in VVSRAT, SAP security note 1619754

SAP Note 1619754

SAP security note 1619754, “Possible directory traversal (1105) in VVSRAT”. Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

There is a read-write or write directory traversal vulnerability in the current DUEVA (DÜVA) download function within statutory reporting for applications in Austria (country variant AT) on the interfaces for Austrian statutory reporting. This issue is present in the following component: FS-SR-AT.

The directory traversal vulnerability with write or read-write authorization allows any data to be read or written using the network.

Solution

Refer to Note 1497003 for additional important information and instructions. The corrections in this note are a crucial prerequisite for implementing Note 1619754.

Reason and prerequisites

A directory traversal vulnerability with write or read-write authorization exists due to an error in the methods that check paths where user-transferred data is written. An attacker can exploit this to transfer any data to the remote system or overwrite existing data. The corresponding solution part DE-V (for insurance companies) has been published in Note 1502330.

CVSS

Score 0

Affected components

  • EA-FINSERV (versions 200, 500, 600, 603, 604, 605, 606)

Full note on SAP: SAP Support Launchpad note 1619754

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More