Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Directory traversal in component FI-CA, SAP security note 1591480

SAP Note 1591480
SAP Security Note
High priority

SAP security note 1591480, "Directory traversal in component FI-CA", was released on 08.11.2011. Below are the symptom, SAP recommended solution and the affected software components.

ComponentFI-CA (Miscellaneous > Project-based solutions > Finance > obsolete: Please use Component FI-CA instead)
PriorityCorrection with high priority
TypeSAP Security Note
Version3
StatusReleased for Customer
Released on08.11.2011
LanguageEnglish

Description

Symptom

Potential directory traversal in the following components:

  • FI-CA

Solution

Implement the correction instructions relevant for your release. For additional information and instructions, see Note 1497003. The corrections from Note 1497003 are a prerequisite for implementing this note.

Logical file names used in this solution:

  • FI-CA-DTA-NAME
  • FI-CA-CHECKS-EXTRACT

Recommendations for setting up logical file names: to avoid maintaining a high number of logical file names, some of the programs share the same logical file name. Using the same logical file name for various programs creates dependencies among these programs. To securely separate data created by different users and different programs, try to create a directory structure that reflects the user name and/or program name, and use this information when setting up the physical path and file names for the logical file paths and file names.

Programs that use these logical file names:

  • RFKKCHK01
  • SAPFKPY3

This note is causing side effects with Note 2375156: Message SG807 in transaction FDTA for FI-CA files.

Reason and prerequisites

The programs specified in the correction instructions contain vulnerabilities through which a malicious user can potentially read arbitrary files on the remote server, possibly disclosing confidential information.

Some of the programs specified in the correction instructions contain a vulnerability through which a malicious user can potentially write arbitrary files on the remote server, possibly corrupting data or altering system behavior.

References

Affected components

  • FI-CA versions 451, 461, 462, 463, 464, 471, 472, 600, 602, 603, 604, 605

Full note on SAP: SAP Support Launchpad note 1591480

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More