Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Directory Traversal / 8 issues/reopen in EDT, SAP security note 1511552

SAP Note 1511552SAP Security NoteHigh priority

SAP security note 1511552, "Directory Traversal / 8 issues/reopen in EDT", is a program error note released on 14.12.2010. Below are the symptom, SAP recommended solution and the affected software components.

ComponentIndustry-Specific Components > Bank > Transaction Datapool > External Data Transfer (IS-B-DP-EDT)
CategoryProgram error
PriorityCorrection with high priority
TypeSAP Security Note
Version4
StatusReleased for Customer
Released on14.12.2010
LanguageEnglish

Description

Symptom

Potential Directory Traversal in the following components: IS-B-DP-EDT.

Solution

Refer to SAP Note 1497003 for additional information and instructions; the corrections from that note are a prerequisite for implementing this note.

Logical file names used in this solution:

  • EDT_FILE_PATH_LOGICAL, which uses the logical file path EDT_FILE_PATH.
  • EDT_LOGICAL_FILE_ALIAS, which uses the logical file path EDT_LOGICAL_FILE.

Reason and prerequisites

The programs contained in the correction instructions have vulnerabilities that allow a malicious user to potentially read arbitrary files on the remote server, possibly disclosing confidential information. Some of these programs also contain vulnerabilities that enable a malicious user to potentially write arbitrary files on the remote server, possibly corrupting data or altering system behavior.

References

Affected components

  • SAP_ABA 620
  • SAP_ABA 640
  • SAP_ABA 700 to 702
  • SAP_ABA 710 to 711
  • SAP_ABA 730

Full note on SAP: SAP Support Launchpad note 1511552

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More