SAP security note 1787032, "FI: Potential Directory Traversal", is a note. Below are the SAP recommended solution and the affected software components.
Description
Solution
Logical file names have been created to validate physical file names:
- FI_IDFI-NL_FILE_NAME
- FI_NOBANK_FILE_NAME
- FI_RFEBNORDIC_FILE_NAME
- FI_RFESR100_FILE_NAME
- FI_RFIDSE_DUNN_EBPOST_FILE_NAME
- FI_RFIDSE_DUNN_INF_FILE_NAME
- FI_SEDUNN_FILE_NAME
These logical file names use the following logical file paths:
- FI_ID-FI-SCAND_FILE_PATH
- FI_ID-FI_FILE_PATH
- FI_ID-OBS_FILE_PATH
After performing the necessary manual activities, apply the attached correction instructions or upgrade to the latest support package.
Reason and prerequisites
1. The programs contained in the correction instructions have vulnerabilities that allow a malicious user to potentially read arbitrary files on the remote server, possibly disclosing confidential information. 2. Some programs also allow a malicious user to potentially write arbitrary files on the remote server, which could corrupt data or alter system behavior.
References
Affected components
- Financial Accounting > Accounts Payable > Basic Functions > Payment transfer (w/o DE, US) (FI-AP-AP-B1)
Full note on SAP: SAP Support Launchpad note 1787032
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




