SAP security note 1584972, "Directory traversal in FI-CA". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Potential directory traversal in the component FI-CA.
Solution
To mitigate this vulnerability, apply the correction instructions provided in Note 1497003 before implementing this note. The corrections include maintaining logical file paths and names via transaction FILE: FI-CA-COL-INFO (Information for Collection Agencies), FI-CA-COL-READ (Information from Collection Agencies), FI-CA-COL-SUB (Submission to Collection Agencies) and FI-CA-COL-TEST (Test file for Collection Agencies).
Reason and prerequisites
The programs specified in the correction instructions contain vulnerabilities that could be exploited to read arbitrary files, potentially disclosing confidential information. Additionally, some programs may allow writing arbitrary files, possibly leading to data corruption or altered system behavior.
CVSS
Score 0
References
- 1775317 – Directory traversal in IS-PS-CA
- 1589424 – Directory traversal in FI-CA
- 1497003 – Potential directory traversals in applications
Affected components
- FI-CA
Full note on SAP: SAP Support Launchpad note 1584972
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




