Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Directory traversal in FI-CA, SAP security note 1584972

SAP Note 1584972

SAP security note 1584972, "Directory traversal in FI-CA". Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

Potential directory traversal in the component FI-CA.

Solution

To mitigate this vulnerability, apply the correction instructions provided in Note 1497003 before implementing this note. The corrections include maintaining logical file paths and names via transaction FILE: FI-CA-COL-INFO (Information for Collection Agencies), FI-CA-COL-READ (Information from Collection Agencies), FI-CA-COL-SUB (Submission to Collection Agencies) and FI-CA-COL-TEST (Test file for Collection Agencies).

Reason and prerequisites

The programs specified in the correction instructions contain vulnerabilities that could be exploited to read arbitrary files, potentially disclosing confidential information. Additionally, some programs may allow writing arbitrary files, possibly leading to data corruption or altered system behavior.

CVSS

Score 0

References

Affected components

  • FI-CA

Full note on SAP: SAP Support Launchpad note 1584972

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More