Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Directory traversal in FI-FM, SAP security note 1599164

SAP Note 1599164
SAP Security Note
High priority

SAP security note 1599164, "Directory Traversal in FI-FM", is a program error note released on August 9, 2011. Below are the symptom, SAP recommended solution and the affected software components.

CategoryProgram error
PriorityCorrection with high priority
TypeSAP Security Note
StatusReleased for Customer
Released onAugust 9, 2011
LanguageEnglish

Description

Symptom

This security note addresses potential directory traversal vulnerabilities in the FI-FM component of SAP Financial Accounting. Specifically, the vulnerabilities allow a malicious user to:

  • Read arbitrary files: potentially disclose confidential information by reading arbitrary files on the remote server.
  • Write arbitrary files: potentially corrupt data or alter system behavior by writing arbitrary files on the remote server.

Solution

  • Apply prerequisite corrections: ensure that all corrections from Note 1497003 are implemented.
  • Validate file names and paths:
    • Logical file name FM_RFFMMDBI_FILE, used by programs RFFMMDBI81 and RFFMMDBI85
    • Logical file path FM_RFFMMDBI_PATH

For detailed instructions, refer to the correction instructions provided in this note.

Reason and prerequisites

The vulnerabilities exist in the programs specified in the correction instructions. To implement the corrections from this note, it is required to first apply Note 1497003, which provides additional information and prerequisite corrections.

References

Affected components

  • SAP_APPL 470, 500, 600, 602, 603, 604, 605

Full note on SAP: SAP Support Launchpad note 1599164

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More