SAP security note 1605054, "Restriction in access to FTP Servers & usage of test reports", is a note released on August 29, 2012. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
FTP function modules previously allowed users to connect to any FTP Server without restrictions, posing a risk where malicious users could write arbitrary files, leading to data corruption or altered system behavior.
Solution
Implement the correction instructions provided in the note, followed by manual configuration to enforce FTP server restrictions and control access to FTP test reports.
- Restrict FTP Test Reports Usage: assign the authority object S_ADMI_FCD with the field SFTP to users responsible for administrative or testing tasks. Refer to Note 1659034 if the SFTP field is unavailable during assignment.
- Maintain FTP Server Whitelist: navigate to transaction SE16. Access the table SAPFTP_SERVERS. Create entries specifying the client, server name, and port to allow access. Alternatively, allow access to any FTP server by setting the server name to *.
CVSS
Score 5.5 Vector: AV:N/AC:L/AU:S/C:P/I:P/A:N
References
- Update #1 to Security Note 1605054
- Directory traversal in SFTP modules
- Maintenance of table SAPFTP_SERVERS changed
Affected components
- SAP_BASIS: 46B, 46C, 620, 640, 700, 710, 711, 720, 730, 731
Full note on SAP: SAP Support Launchpad note 1605054
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
