SAP Security Note
High priority
SAP security note 1619630, “Directory traversal in RPLQSTC3”, is a program error note released on 08.11.2011. Below are the symptom and SAP recommended solution.
Description
Symptom
RPLQSTC3 contains a vulnerability through which a malicious user can potentially write arbitrary files on the remote server, possibly corrupting data or altering system behavior.
Solution
In the report RPLQSTC3 (Withholding Tax Statement for Geneva Attestation/Quittance), the option of the file interface for “Formalix” (up to the 2009 fiscal year) “Download to Application Server” can no longer be selected.
Import the HR Support Package specified for your release, or implement the relevant correction instructions.
Reason and prerequisites
RPLQSTC3 fails to correctly validate the path to which a user-submitted file is written. As a result, a malicious user can potentially overwrite data in the remote system.
References
This note refers to
Full note on SAP: SAP Support Launchpad note 1619630
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
