SAP Security Note
Medium priority
SAP security note 1783772, “FI: Potential Directory Traversal – Argentina”, is a program error note released on 21.04.2015. Below are the symptom and SAP recommended solution.
Description
Symptom
Potential Directory Traversal in the following components: XX-CSC-AR
Solution
Please refer to SAP Note 1497003 for additional information and instructions. The corrections from note 1497003 are a prerequisite for implementing this note.
- Logical File Name: FI_J1AF317_FILE
- Logical File Path: FI_AR_FILE_PATH
Reason and prerequisites
The programs contained in the correction instructions have vulnerabilities that allow malicious users to read or write arbitrary files on the remote server, potentially disclosing confidential information or corrupting data.
References
This note refers to
Referenced by
Full note on SAP: SAP Support Launchpad note 1783772
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
