SAP Security Note
High priority
SAP security note 1599072, "Directory traversal in RE-BD", is a program error note released on 09.08.2011. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
RE-BD contains a vulnerability through which a malicious user can potentially write arbitrary files on the remote server, possibly corrupting data or altering system behavior.
Solution
The programs contained in the correction instructions are used in RE-BD (RE-Classic) for legacy data transfer. As RE-Classic is an old product (see also note 443311) for which the successor product RE-FX exists, SAP decided to remove the critical coding inside the programs contained in the correction instructions. After implementing the correction, the programs do not work any longer. If you use these programs nevertheless, please submit a customer message under subject area RE-BD with reference to this note.
Reason and prerequisites
RE-BD fails to correctly validate the path to which a user-submitted file is written. As a result, a malicious user can potentially overwrite data in the remote system.
References
- 1574302 – Directory traversal in RE-BD and RE-RT
- 1509424 – RE-Classic Potential Directory Traversal
- 1497003 – Potential directory traversals in applications
- 888889 – Automatic checks for security notes using RSECNOTE (outdated)
Affected components
- SAP_APPL 40B to 605
Full note on SAP: SAP Support Launchpad note 1599072
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
