SAP Security Note
High priority
SAP security note 1589715, “Directory traversal in card application component”, is a program error note released on 13.09.2011. Below are the symptom and SAP recommended solution.
Description
Symptom
The card application component contains a vulnerability through which a malicious user can potentially write arbitrary files on the remote server, possibly corrupting data or altering system behavior.
Solution
Import the relevant Support Package for your release.
For more information and instructions, see Note 1497003. Before you can implement this note, you must have implemented the corrections from Note 1497003.
- Logical file CARD_CONSISTENCY_CHECK maps to BCA_CARD_TEST_FILE.
- Logical file CARD_TRANSFER_FILE maps to BCA_CARD_TEST_FILE.
- Logical file CCPP_CONSISTENCY_CHECK maps to BCA_CARD_ORDER_TEST_FILE.
- Logical file path BCA_AM_CONSISTENT_PATH is used for BCA_CARD_TEST_FILE and BCA_CARD_ORDER_TEST_FILE.
Reason and prerequisites
The card application component fails to correctly validate the path to which a user-submitted file is written. As a result, a malicious user can potentially overwrite data in the remote system.
References
Full note on SAP: SAP Support Launchpad note 1589715
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



