SAP Security Note
High priority
SAP security note 1607944, “Directory traversal vulnerability in IS-H-CM components”, is released on 13.10.2011. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
There is a potential directory traversal vulnerability in the following components:
- IS-H-CM-INS
- IS-H-CM-OUT
Solution
Logical file names must be validated to prevent unauthorized file access. The following logical file names have been created for validation:
- RNC301I0: Validation for IS-H EDI File Import Program
Recommendations:
- Avoid maintaining a high number of logical file names by sharing the same logical file name across various programs.
- Create a directory structure that reflects the user name and/or program name to securely separate data.
Steps to Implement:
- Call transaction FILE.
- Navigate to “Logical File Path Definition, Cross-Client.”
- Choose New Entries.
- Enter the following data for all file names and texts: Logical file: <FILE NAME>; Name: <TEXT>; Data format: DIR; Application area: IS.
- Save your changes.
Example: File Name: RNC301I0; Text: Validation for IS-H EDI File Import Program.
Reason and prerequisites
The programs specified in the correction instructions contain vulnerabilities that allow a malicious user to:
- Read arbitrary files on the remote server, potentially disclosing confidential information.
- Write arbitrary files on the remote server, possibly corrupting data or altering system behavior.
References
Affected components
- IS-H – Versions 463B, 471, 472, 600, 602, 603, 604, 605
Full note on SAP: SAP Support Launchpad note 1607944
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
