SAP Security Note
High priority
SAP security note 1590016, “FI-CA: Potential Directory Traversal”, released on 13.09.2011. Below are the symptom and SAP recommended solution.
Description
Symptom
Potential Directory Traversal in the following component:
- XX-CSC-BE-FICA
Solution
Follow these steps to apply the correction:
- Go to transaction FILE. Under “Logical file path definition”, create a new entry for logical file path “FICA_FKK_ID_BE_FILE_PATH” with the name “File path for BE report”.
- Under “logical file name definition”, create a new entry: logical file “FI-CA_RFKKBEINC000_FILE”, name “FICA”, application area “IS”, logical path “FICA_FKK_ID_BE_FILE_PATH”.
Reason and prerequisites
1. The programs contained in the correction instructions have vulnerabilities that allow a malicious user to potentially read arbitrary files on the remote server, possibly disclosing confidential information.
2. Some programs within the correction instructions contain a vulnerability that allows a malicious user to potentially write arbitrary files on the remote server, possibly corrupting data or altering system behavior.
Full note on SAP: SAP Support Launchpad note 1590016
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
