Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Directory Traversal Vulnerability in FSB, SAP security note 2355339

SAP Note 2355339
SAP Security Note
Medium priority

SAP security note 2355339, “Directory Traversal Vulnerability in FSB”, released on January 25, 2017. Below are the symptom and SAP recommended solution.

ComponentSales and Distribution > Billing > Processing Billing Documents > Consolidated Billing (SD-BIL-IV-CB)
PriorityCorrection with medium priority
TypeSAP Security Note
Version2
StatusReleased for Customer
Released onJanuary 25, 2017

Description

Symptom

Flexible Solution Billing (FSB) allows an attacker to exploit insufficient validation of path information provided by users, wherein characters representing ‘traverse to parent directory’ are passed through to the file APIs.

  • Attackers could read content of arbitrary files on the remote server and expose sensitive data.
  • Attackers could overwrite, delete, or corrupt arbitrary files on the remote server.

Solution

The logical file name is now fixed and read-only. Users can no longer arbitrarily choose logical file names.

Refer to the “Support Packages & Patches” section for support packages containing the correction. Alternatively, implement the provided correction instructions.

Reason and prerequisites

FSB fails to correctly restrict access via logical file names where application data is not stored.

CVSS

Score 0

Full note on SAP: SAP Support Launchpad note 2355339

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More