SAP Security Note
High priority
SAP security note 1775171, “Directory traversal in FI-CA”, is a program error note released on 11.12.2012. Below are the symptom and SAP recommended solution.
Description
Symptom
FI-CA contains a vulnerability through which an attacker can potentially write arbitrary files to the remote server, possibly corrupting data or altering system behavior.
Solution
Implement the correction instructions relevant for your release.
For additional information and instructions, see SAP Note 1497003. The corrections from SAP Note 1497003 are a prerequisite for implementing this note.
Logical file names used in this solution:
- FI-CA-CVS
Logical file names used in this solution are created by implementing the corrections from SAP Note 1507122. SAP Note 1507122 is a prerequisite for the corrections from this SAP Note. The logical file name FI-CA-CVS is reused in the corrections.
Reason and prerequisites
FI-CA fails to correctly validate the path to which a user-submitted file is written. As a result, an attacker can potentially overwrite data in the remote system.
References
Full note on SAP: SAP Support Launchpad note 1775171
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
