SAP security note 1614897, “Directory traversal in IS-H-PA, IS-H-IS-GMS, IS-H-CM-OUT”. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
SAP Security Note 1614897 addresses potential directory traversal vulnerabilities in the following components: IS-H-PA (Patient Accounting), IS-H-IS-GMS (Government-Mandated Statistics) and IS-H-CM-OUT (Communication with Systems Outside the Hospital).
These vulnerabilities may allow malicious users to:
- Read arbitrary files on the remote server, potentially disclosing confidential information.
- Write arbitrary files on the remote server, possibly corrupting data or altering system behavior.
Solution
To resolve these vulnerabilities, follow these steps:
- Prerequisites: implement the corrections from Note 1497003. These corrections are necessary before applying this note.
- Logical File Names: introduce the logical file name RNAP21F01, delivered with Note 1607749.
- Setup Recommendations: create a directory structure reflecting user and/or program names to securely separate data, and use this structure when setting up physical paths and file names for logical file paths and file names.
References
- 1607749 – Directory traversal in IS-H, central program part
- 1526102 – IS-H: Directory Traversal Vulnerability in IS-H
Affected components
- IS-H (463B, 472, 600, 602, 603, 604, 605)
Full note on SAP: SAP Support Launchpad note 1614897
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
