SAP security note 1533500, "Argentina J1ACAE: Potential Directory Traversal". Below are the symptom and the SAP recommended solution.
Description
Symptom
Potential Directory Traversal for J_1A_CAE.
Solution
Please refer to Note 1497003 for additional information and instructions. The corrections from Note 1497003 are a prerequisite for the implementation of this note.
The following logical file name has been created to enable the validation of physical file names: FI_J1ACAE_FILE, used by program J_1A_CAE. The application J_1A_CAE passes an additional parameter <PARAM_1> (program name, sy-cprog) to the function module FILE_VALIDATE_NAME. This allows a customer to insert the parameter while configuring the physical paths for the logical file name FI_J1ACAE_FILE. Logical file path used in this solution: FI_AEI_FILE_PATH.
Reason and prerequisites
The program contained in the correction instructions has vulnerabilities that allow a malicious user to potentially read or write arbitrary files on the remote server, possibly disclosing, corrupting, or altering confidential information.
References
- Note 1603934 – Directory Traversal in XX-CSC-AR
- Note 1497003 – Potential directory traversals in applications
Full note on SAP: SAP Support Launchpad note 1533500
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
