SAP security note 1785662, "Directory traversal in external billing interface", is a note. Below are the symptom and SAP recommended solution.
Description
Symptom
Billing via the internal billing interface (reports RVAFSS00, RVAFSS01, and RVAFSS02) contains a vulnerability that allows an attacker to potentially read arbitrary files on the remote server, potentially disclosing confidential information.
Solution
For additional information and instructions, refer to Note 1497003 and Note 1605703. The corrections from these notes are prerequisites for implementing this note.
Reason and prerequisites
Reports RVAFSS00, RVAFSS01, and RVAFSS02 fail to correctly validate the file path used to reference files read from the remote server. As a result, an attacker can direct the program to arbitrary files in the system, disclosing their contents.
Full note on SAP: SAP Support Launchpad note 1785662
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
