SAP security note 1619754, “Possible directory traversal (1105) in VVSRAT”. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
There is a read-write or write directory traversal vulnerability in the current DUEVA (DÜVA) download function within statutory reporting for applications in Austria (country variant AT) on the interfaces for Austrian statutory reporting. This issue is present in the following component: FS-SR-AT.
The directory traversal vulnerability with write or read-write authorization allows any data to be read or written using the network.
Solution
Refer to Note 1497003 for additional important information and instructions. The corrections in this note are a crucial prerequisite for implementing Note 1619754.
Reason and prerequisites
A directory traversal vulnerability with write or read-write authorization exists due to an error in the methods that check paths where user-transferred data is written. An attacker can exploit this to transfer any data to the remote system or overwrite existing data. The corresponding solution part DE-V (for insurance companies) has been published in Note 1502330.
CVSS
Score 0
Affected components
- EA-FINSERV (versions 200, 500, 600, 603, 604, 605, 606)
Full note on SAP: SAP Support Launchpad note 1619754
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
