SAP security note 1961946, "Directory Traversal Vulnerability in /CCEE/FISIFP_1450". Below are the symptom, reason and prerequisites, SAP recommended solution and the affected software components.
Description
Symptom
/CCEE/FISIFP_1450 contains a vulnerability that allows an attacker to potentially write arbitrary files to the remote server, possibly corrupting data or altering system behavior.
Solution
SAP recommends installing a solution by applying a Support Package. If an immediate solution is required, follow these steps using the Note Assistant:
- Apply Manual Corrections: follow the instructions provided in the attached document.
- Apply Code Corrections: use transaction SNOTE to apply the code correction instructions from this note.
- Prerequisite Note: ensure that Note 1497003 is implemented, as its corrections are necessary for this note.
A new logical file name has been created to validate physical file names: /CCEE/SIFI
To minimize the number of logical file names and avoid dependencies among programs, design a directory structure that reflects the user name and/or program name, and use this structure when setting up the physical path and file names to securely separate data created by different users and programs.
For more information about the Note Assistant, visit the SAP Service Marketplace.
Reason and prerequisites
The vulnerability exists because /CCEE/FISIFP_1450 fails to correctly validate the path to which a user-submitted file is written. As a result, an attacker can potentially overwrite data in the remote system.
Affected components
- C-CEE 110_600
- C-CEE 110_602
- C-CEE 110_603
- C-CEE 110_604
Full note on SAP: SAP Support Launchpad note 1961946
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
