SAP Security Note
High priority
SAP security note 1593164, "Directory Traversal in Treasury Confirmation", is a program error note released on June 12, 2012. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
SAP Security Note 1593164 addresses a Directory Traversal vulnerability in the Treasury Confirmation (PSM-FG-TC) component. This vulnerability allows attackers to potentially read or write arbitrary files on the remote server, which can lead to the disclosure of confidential information or corruption of data/system behavior.
- Read arbitrary files: certain programs may allow attackers to read arbitrary files on the server, potentially exposing confidential information.
- Write arbitrary files: vulnerable programs may permit attackers to write arbitrary files, leading to data corruption or altered system behavior.
Solution
- Prerequisite: ensure that Note 1497003 is implemented as it provides necessary corrections for this issue.
- Create logical file/path names: PSM_AUTO_TC_CREATE_PATH / PSM_AUTO_TC_CREATE_FILE, PSM_AUTO_TC_SWIFT_CREATE_PATH / PSM_AUTO_TC_SWIFT_CRE_FILE.
- Recommendations: minimize the number of logical file names by sharing them across programs where feasible; structure directories to reflect user and program names to securely separate data.
- Apply source code corrections: follow the attached correction instructions in the note.
References
- SAP Note 1863678 – FMFG_AUTO_TC: SLIN_SEC message during transaction CHECKMAN
- SAP Note 1497003 – Potential directory traversals in applications
Affected components
- EA-PS 110
- EA-PS 200
- EA-PS 500
- EA-PS 600
- EA-PS 603
- EA-PS 604
- EA-PS 605
- EA-PS 606
- EA-PS 616
Full note on SAP: SAP Support Launchpad note 1593164
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
