SAP security note 1591939, "IS-H NL: Directory/Path Traversal", is a note. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
XX-CSC-NL-IS-H contains a vulnerability through which a malicious user can potentially write arbitrary files on the remote server, possibly corrupting data or altering system behaviour.
Solution
For additional information and instructions, see Note 1497003. The corrections from Note 1497003 are a prerequisite for implementing this note.
Logical file names used in this solution. The following logical file names have been used to enable the validation of the physical files:
- CL_ISH_NL_CINV_VIEWER
- CL_ISH_NL_FILE
- RNNLDIS_CZ_V5
- RNNLGGZ_DIS_V04
- RNU_NL_LOAD_DBC_COMP
To avoid maintaining a high number of logical file names, some of the programs share the same logical file name. Using the same logical file name for various programs creates dependencies among these programs. To securely separate data created by different users and different programs, try to create a directory structure that reflects the user name and/or program name, and use this information when setting up the physical path and file names for the logical file paths and file names.
Reason and prerequisites
XX-CSC-NL-IS-H fails to correctly validate the path to which a user-submitted file is written. As a result, a malicious user can potentially overwrite data in the remote system.
Affected components
- IS-H 472
- IS-H 600
- IS-H 602
- IS-H 603
- IS-H 604
- IS-H 605
Full note on SAP: SAP Support Launchpad note 1591939
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
