SAP Security Note
High priority
SAP security note 1598990, "FI: Potential Directory Traversal- Korea", is a program error note released on 08.11.2011. Below are the symptom and SAP recommended solution.
Description
Symptom
Potential Directory Traversal for RFUMSV45R.
Solution
Please refer to note 1497003 for additional information and instructions. The corrections from note 1497003 are a prerequisite for the implementation of this note.
Logical File Name Used in this Solution: FI_RFUMSV45R_FILE
Program Using this Logical Filename: RFUMSV45R
Logical File Path Used in this Solution: FI_RFUMSV45R_PATH
The application RFUMSV45R is passing an additional parameter parameter_1 (sy-cprog) to the Function Module FILE_VALIDATE_NAME. This allows a customer to insert the parameter while configuring the physical paths for the Logical File Name FI_RFUMSV45R_FILE.
Reason and prerequisites
The programs contained in the correction instructions have vulnerabilities that allow a malicious user to potentially read arbitrary files on the remote server, possibly disclosing confidential information. Some programs in the correction instructions have vulnerabilities that allow a malicious user to potentially write arbitrary files on the remote server, possibly corrupting data or altering system behavior.
References
This note refers to
Full note on SAP: SAP Support Launchpad note 1598990
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




