Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Bank statement Potential directory traversal, SAP security note 1595064

SAP Note 1595064

SAP security note 1595064, "Bank statement: Potential directory traversal". Below are the symptom, SAP recommended solution and the affected software components.

ComponentFI-BL-PT-BA

Description

Symptom

There’s a potential directory traversal vulnerability in the component FI-BL-PT-BA. This issue allows a malicious user to potentially write files using the network, which could compromise the integrity and security of the system.

Solution

To address this vulnerability:

  • Apply correction instructions: follow the detailed correction steps outlined in the Correction Instructions for Note 1595064.
  • Ensure prerequisites: make sure that Note 1497003 is applied before implementing this security note.
  • Validate logical file names: the solution involves validating physical file names using the following logical file names: FI_RFEBDK00_FILE, FI_RFEBFI00_FILE, FI_RFEBSE00_FILE. These are used in the programs: RFEBDK00, RFEBFI00, RFEBSE00.

Reason and prerequisites

Some programs specified in the correction instructions contain an error that facilitates this vulnerability. Implementing the correction requires applying Note 1497003 as a prerequisite.

Affected components

  • SAP_APPL versions from 31I to 605 within various subcomponents.
  • SAP_BASIS versions 46B to 730.

Full note on SAP: SAP Support Launchpad note 1595064

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More