SAP security note 1884212, "Bank statement: Potential directory traversal", is a note released on November 12, 2013. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
An attacker can exploit the directory traversal vulnerability in FI-BL-PT-BA to overwrite data on the remote system.
Solution
Implement SAP Security Note 1884212 to address the vulnerability.
Reason and prerequisites
The FI-BL-PT-BA component fails to correctly validate the file path for user-submitted files. This lack of validation permits attackers to overwrite data on the remote system.
Affected components
- SAP_APPL (Versions 500 to 616)
- SAP_FIN (Version 617)
Full note on SAP: SAP Support Launchpad note 1884212
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
