SAP Security Note
Medium priority
SAP security note 1861588, "Directory Traversal Vulnerability in XX-CSC-PT-FIAA", is a note released on July 7, 2015. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
A directory traversal vulnerability exists in the XX-CSC-PT-FIAA component. This flaw allows an attacker to potentially write arbitrary files to the remote server, which could lead to data corruption or alteration of system behavior.
Solution
To address this vulnerability, apply the correction instructions provided with this note or upgrade to the relevant support package.
References
This note refers to
- SAP Note 1497003 – potential directory traversals in applications
Affected components
- SAP_APPL 46C, 470, 500, 600, 602, 603, 604, 605, 606, 616
- SAP_FIN 617
Full note on SAP: SAP Support Launchpad note 1861588
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
