Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Directory Traversal in PP-BD-RTG, SAP security note 1590299

SAP Note 1590299

SAP security note 1590299, "Directory Traversal in PP-BD-RTG", is a note. Below are the symptom and SAP recommended solution.

Description

Symptom

Potential directory traversal in the following components: PP-BD-RTG.

Solution

For additional information and instructions, see Note 1497003. The corrections provided in Note 1497003 are a prerequisite for implementing this note.

The following logical file names have been created to enable the validation of the following logical file names:

  • CP_RTG_DATA_LOAD

To avoid maintaining a high number of logical file names, some of the programs share the same logical file name.

Using the same logical file name for various programs creates dependencies among these programs. To securely separate data created by different users and different programs, try to create a directory structure that reflects the user name and/or program name, and use this information when setting up the physical path and file names for the logical file paths and file names.

Reason and prerequisites

The programs specified in the correction instructions contain vulnerabilities through which a malicious user can potentially read arbitrary files on the remote server, possibly disclosing confidential information.

Some of the programs specified in the correction instructions contain a vulnerability through which a malicious user can potentially write arbitrary files on the remote server, possibly corrupting data or altering system behavior.

References

Full note on SAP: SAP Support Launchpad note 1590299

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More