High priority
SAP security note 1502329, "Directory Traversal Vulnerability in FS-SR-AT", is a note released on December 14, 2010. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
The directory traversal issue affects the reports RFVZWPD1, RFVZWPD2, and RFVZFIMA in the old regulatory reporting solution for Austria. This flaw allows attackers to manipulate data paths, enabling them to read or write data to unintended directories over the network.
Solution
To mitigate this vulnerability, refer to Note 1497003 for important information and instructions. Implementing the corrections in Note 1497003 is a crucial prerequisite for applying this note.
Logical file names and paths have been created to validate physical file names and paths, ensuring that only authorized data access and modifications are possible.
References
Full note on SAP: SAP Support Launchpad note 1502329
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
