SAP Security Note
Medium priority
SAP security note 1953975, "Directory traversal in /CCEE/YUFI_RFEBHALC00", is a program error note released on 18.02.2014. Below are the symptom, reason and prerequisites, SAP recommended solution, CVSS score and related references.
Description
Symptom
/CCEE/YUFI_RFEBHALC00 contains a vulnerability that allows an attacker to potentially read arbitrary files on the remote server, disclosing confidential information. Additionally, the vulnerability allows writing arbitrary files to the remote server, possibly corrupting data or altering system behavior.
Solution
SAP recommends installing a solution by applying a Support Package. If an earlier installation is necessary, use the Note Assistant and follow these instructions:
- Apply manual corrections as provided in the attachment.
- Apply code correction instructions from the note using transaction SNOTE.
- Ensure that Note 1497003 is implemented, as its corrections are prerequisites for this note.
A logical file name /CCEE/YUFI has been created to validate physical file names. To maintain security and reduce the number of logical file names, organize directory structures to reflect user and program names, ensuring secure separation of data.
More information about the Note Assistant can be found on SAP Service Marketplace.
Reason and prerequisites
The vulnerability arises because /CCEE/YUFI_RFEBHALC00 fails to correctly validate the file path used for reading and writing. This allows an attacker to manipulate the file path to access or overwrite arbitrary files within the system.
CVSS
Score 0
References
Full note on SAP: SAP Support Launchpad note 1953975
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
