SAP security note 1589355, "Directory traversal in Bank Analyzer". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Bank Analyzer contains a vulnerability through which a malicious user can potentially write arbitrary files on the remote server, possibly corrupting data or altering system behavior.
Solution
Please apply the correction from SAP Note 1589355.
Reason and prerequisites
Bank Analyzer fails to correctly validate the path to which a user-submitted file is written. As a result, a malicious user can potentially overwrite data in the remote system.
References
Affected components
- FSAPPL
- BANK-ALYZE
Full note on SAP: SAP Support Launchpad note 1589355
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




