SAP security note 1589424, "Directory traversal in FI-CA", is a note released on July 12, 2011. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
FI-CA contains a vulnerability that allows a malicious user to read arbitrary files on the remote server, potentially disclosing confidential information, or write arbitrary files on the remote server, potentially corrupting data or altering system behavior.
Solution
Ensure that Note 1497003 is applied; it provides necessary corrections that must be in place before implementing the solution for this note. Depending on your FI-CA version, apply the appropriate support package.
References
- 1602943 – FI-CA Potential directory traversal
- 1584972 – Directory traversal in FI-CA
- 1507122 – FI-CA Potential Directory Traversal
- 1497003 – Potential directory traversals in applications
Affected components
- FI-CA
Full note on SAP: SAP Support Launchpad note 1589424
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
