SAP Security Note
High priority
SAP security note 1591480, "Directory traversal in component FI-CA", was released on 08.11.2011. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Potential directory traversal in the following components:
- FI-CA
Solution
Implement the correction instructions relevant for your release. For additional information and instructions, see Note 1497003. The corrections from Note 1497003 are a prerequisite for implementing this note.
Logical file names used in this solution:
- FI-CA-DTA-NAME
- FI-CA-CHECKS-EXTRACT
Recommendations for setting up logical file names: to avoid maintaining a high number of logical file names, some of the programs share the same logical file name. Using the same logical file name for various programs creates dependencies among these programs. To securely separate data created by different users and different programs, try to create a directory structure that reflects the user name and/or program name, and use this information when setting up the physical path and file names for the logical file paths and file names.
Programs that use these logical file names:
- RFKKCHK01
- SAPFKPY3
This note is causing side effects with Note 2375156: Message SG807 in transaction FDTA for FI-CA files.
Reason and prerequisites
The programs specified in the correction instructions contain vulnerabilities through which a malicious user can potentially read arbitrary files on the remote server, possibly disclosing confidential information.
Some of the programs specified in the correction instructions contain a vulnerability through which a malicious user can potentially write arbitrary files on the remote server, possibly corrupting data or altering system behavior.
References
- Note 534245: CR: Positive Payment interface – callup point 249
- Note 1064779: PMF: Use alternative code page (FI-CA 600)
- Note 1487491: CR: Reporting file FPCHX with voided checks only
- Note 1501267: PMF: SEPA obstructive CR/LF for XML
- Note 1538956: CR: FPCHX reporting file with name in case of repayments
- Note 1624291: Syntax error when implementing a security note
Affected components
- FI-CA versions 451, 461, 462, 463, 464, 471, 472, 600, 602, 603, 604, 605
Full note on SAP: SAP Support Launchpad note 1591480
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
