SAP security note 1595064, "Bank statement: Potential directory traversal". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
There’s a potential directory traversal vulnerability in the component FI-BL-PT-BA. This issue allows a malicious user to potentially write files using the network, which could compromise the integrity and security of the system.
Solution
To address this vulnerability:
- Apply correction instructions: follow the detailed correction steps outlined in the Correction Instructions for Note 1595064.
- Ensure prerequisites: make sure that Note 1497003 is applied before implementing this security note.
- Validate logical file names: the solution involves validating physical file names using the following logical file names:
FI_RFEBDK00_FILE,FI_RFEBFI00_FILE,FI_RFEBSE00_FILE. These are used in the programs:RFEBDK00,RFEBFI00,RFEBSE00.
Reason and prerequisites
Some programs specified in the correction instructions contain an error that facilitates this vulnerability. Implementing the correction requires applying Note 1497003 as a prerequisite.
Affected components
- SAP_APPL versions from 31I to 605 within various subcomponents.
- SAP_BASIS versions 46B to 730.
Full note on SAP: SAP Support Launchpad note 1595064
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
