SAP Security Note
Medium priority
SAP security note 2355339, “Directory Traversal Vulnerability in FSB”, released on January 25, 2017. Below are the symptom and SAP recommended solution.
Description
Symptom
Flexible Solution Billing (FSB) allows an attacker to exploit insufficient validation of path information provided by users, wherein characters representing ‘traverse to parent directory’ are passed through to the file APIs.
- Attackers could read content of arbitrary files on the remote server and expose sensitive data.
- Attackers could overwrite, delete, or corrupt arbitrary files on the remote server.
Solution
The logical file name is now fixed and read-only. Users can no longer arbitrarily choose logical file names.
Refer to the “Support Packages & Patches” section for support packages containing the correction. Alternatively, implement the provided correction instructions.
Reason and prerequisites
FSB fails to correctly restrict access via logical file names where application data is not stored.
CVSS
Score 0
Full note on SAP: SAP Support Launchpad note 2355339
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
