SAP security note 1574333, “Directory traversal in RE-RT-SC”. Below are the symptom and SAP recommended solution.
Description
Symptom
Potential directory traversal in the following components: RE-RT-SC.
Solution
For additional information and instructions, see Note 1497003. The corrections provided in Note 1497003 are a prerequisite for implementing this note.
Logical file names used in this solution:
- IS_RE_CREATE_TAPE
- IS_RE_STATUS_COSTCOLLECTOR
Recommendations for setting up logical file names: To avoid maintaining a high number of logical file names, some of the programs share the same logical file name. Using the same logical file name for various programs creates dependencies among these programs. To securely separate data created by different users and different programs, try to create a directory structure that reflects the user name and/or program name, and use this information when setting up the physical path and file names for the logical file paths and file names.
Reason and prerequisites
Some of the programs specified in the correction instructions contain a vulnerability through which a malicious user can potentially write arbitrary files on the remote server, possibly corrupting data or altering system behavior.
Full note on SAP: SAP Support Launchpad note 1574333
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
