Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Directory Traversal in SAP Payment Engine, SAP security note 1509915

SAP Note 1509915

SAP security note 1509915, "Directory Traversal in SAP Payment Engine". Below are the symptom and SAP recommended solution.

Description

Symptom

An error in the SAP Payment Engine allows any files to be read using the network.

Solution

See Note 1497003 for additional information and instructions. You must implement the corrections from Note 1497003 before you implement this note.

The following logical file names were created to activate the validation of the physical file names:

  • /PE2/PMCF_INPUT_FILE

The logical file name mentioned above uses the file path /PE2/PMCF_INPUT_PATH.

Reason and prerequisites

The programs listed in the attached correction instructions contain a vulnerability through which a malicious user can potentially read arbitrary files on the remote server, possibly disclosing confidential information.

Some of the programs listed in the attached correction instructions contain a vulnerability through which a malicious user can potentially write arbitrary files on the remote server, possibly corrupting data or altering system behaviour.

Full note on SAP: SAP Support Launchpad note 1509915

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More