SAP Security Note
High priority
SAP security note 1599164, "Directory Traversal in FI-FM", is a program error note released on August 9, 2011. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
This security note addresses potential directory traversal vulnerabilities in the FI-FM component of SAP Financial Accounting. Specifically, the vulnerabilities allow a malicious user to:
- Read arbitrary files: potentially disclose confidential information by reading arbitrary files on the remote server.
- Write arbitrary files: potentially corrupt data or alter system behavior by writing arbitrary files on the remote server.
Solution
- Apply prerequisite corrections: ensure that all corrections from Note 1497003 are implemented.
- Validate file names and paths:
- Logical file name
FM_RFFMMDBI_FILE, used by programsRFFMMDBI81andRFFMMDBI85 - Logical file path
FM_RFFMMDBI_PATH
- Logical file name
For detailed instructions, refer to the correction instructions provided in this note.
Reason and prerequisites
The vulnerabilities exist in the programs specified in the correction instructions. To implement the corrections from this note, it is required to first apply Note 1497003, which provides additional information and prerequisite corrections.
References
Affected components
- SAP_APPL 470, 500, 600, 602, 603, 604, 605
Full note on SAP: SAP Support Launchpad note 1599164
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
