SAP security note 1987773, “Directory traversal in XX-CSC-AR-FICA”, is a note released on 12.08.2014. Below is the security information published by SAP for this note.
Description
Symptom
XX-CSC-AR-FICA contains a vulnerability that allows an attacker to potentially:
- Read arbitrary files on the remote server, possibly disclosing confidential information.
- Write arbitrary files to the remote server, potentially corrupting data or altering system behavior.
Reason and prerequisites
XX-CSC-AR-FICA fails to properly validate file paths used to read from or write to the remote server:
- Reading Files: Allows directing the program to arbitrary files in the system, disclosing contents.
- Writing Files: Allows overwriting data in the remote system.
Solution
Implement the provided correction instructions to resolve the vulnerabilities.
Affected components
- FI-CA: Versions 606 and 616
Full note on SAP: SAP Support Launchpad note 1987773
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
