Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Directory Traversal vulnerability in IS-OIL-PRA-REP-TAX and IS-OIL-PRA-REP-ROY, SAP security note 2174147

SAP Note 2174147

SAP security note 2174147, “Directory Traversal vulnerability in IS-OIL-PRA-REP-TAX and IS-OIL-PRA-REP-ROY”. Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

IS-OIL-PRA-REP-TAX and IS-OIL-PRA-REP-ROY contain vulnerabilities that allow an attacker to:

  • Read arbitrary files on the remote server, potentially disclosing confidential information.
  • Write arbitrary files to the remote server, potentially corrupting data or altering system behavior.

Solution

Code corrections have been implemented and are available in this SAP Note. Specifically, input parameters that could introduce security issues have been commented out and are no longer utilized in the programs.

Reason and prerequisites

IS-OIL-PRA-REP-TAX and IS-OIL-PRA-REP-ROY fail to correctly validate the file paths used to reference and write files on the remote server. This allows attackers to manipulate file paths to access or modify unintended files.

CVSS

Score 0

Affected components

  • IS-OIL 46C
  • IS-OIL 600
  • IS-OIL 602
  • IS-OIL 603
  • IS-PRA 604
  • IS-PRA 605
  • IS-PRA 606
  • IS-PRA 616
  • IS-PRA 617

Full note on SAP: SAP Support Launchpad note 2174147

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More