Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

FI Potential Directory Traversal, SAP security note 1787032

SAP Note 1787032

SAP security note 1787032, "FI: Potential Directory Traversal", is a note. Below are the SAP recommended solution and the affected software components.

Description

Solution

Logical file names have been created to validate physical file names:

  • FI_IDFI-NL_FILE_NAME
  • FI_NOBANK_FILE_NAME
  • FI_RFEBNORDIC_FILE_NAME
  • FI_RFESR100_FILE_NAME
  • FI_RFIDSE_DUNN_EBPOST_FILE_NAME
  • FI_RFIDSE_DUNN_INF_FILE_NAME
  • FI_SEDUNN_FILE_NAME

These logical file names use the following logical file paths:

  • FI_ID-FI-SCAND_FILE_PATH
  • FI_ID-FI_FILE_PATH
  • FI_ID-OBS_FILE_PATH

After performing the necessary manual activities, apply the attached correction instructions or upgrade to the latest support package.

Reason and prerequisites

1. The programs contained in the correction instructions have vulnerabilities that allow a malicious user to potentially read arbitrary files on the remote server, possibly disclosing confidential information. 2. Some programs also allow a malicious user to potentially write arbitrary files on the remote server, which could corrupt data or alter system behavior.

References

Affected components

  • Financial Accounting > Accounts Payable > Basic Functions > Payment transfer (w/o DE, US) (FI-AP-AP-B1)

Full note on SAP: SAP Support Launchpad note 1787032

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More