Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Directory traversal in IS-H-CM, SAP security note 1607944

SAP Note 1607944
SAP Security Note
High priority

SAP security note 1607944, “Directory traversal vulnerability in IS-H-CM components”, is released on 13.10.2011. Below are the symptom, SAP recommended solution and the affected software components.

ComponentIS-H-CM (Industry-Specific Components > Hospital > Communication)
PriorityHigh priority
TypeSAP Security Note
Version3
StatusReleased for Customer
Released on13.10.2011

Description

Symptom

There is a potential directory traversal vulnerability in the following components:

  • IS-H-CM-INS
  • IS-H-CM-OUT

Solution

Logical file names must be validated to prevent unauthorized file access. The following logical file names have been created for validation:

  • RNC301I0: Validation for IS-H EDI File Import Program

Recommendations:

  • Avoid maintaining a high number of logical file names by sharing the same logical file name across various programs.
  • Create a directory structure that reflects the user name and/or program name to securely separate data.

Steps to Implement:

  • Call transaction FILE.
  • Navigate to “Logical File Path Definition, Cross-Client.”
  • Choose New Entries.
  • Enter the following data for all file names and texts: Logical file: <FILE NAME>; Name: <TEXT>; Data format: DIR; Application area: IS.
  • Save your changes.

Example: File Name: RNC301I0; Text: Validation for IS-H EDI File Import Program.

Reason and prerequisites

The programs specified in the correction instructions contain vulnerabilities that allow a malicious user to:

  • Read arbitrary files on the remote server, potentially disclosing confidential information.
  • Write arbitrary files on the remote server, possibly corrupting data or altering system behavior.

References

Affected components

  • IS-H – Versions 463B, 471, 472, 600, 602, 603, 604, 605

Full note on SAP: SAP Support Launchpad note 1607944

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More