SAP Security Note
High priority
SAP security note 1511617, "FI-BL-PT-FO: Possible directory traversal", is a program error note released on 12.01.2011. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Component FI-BL-PT-FO: Potential directory traversal
This security note has been updated. For more information see security note 1538366.
Solution
See 1497003 for additional information on this issue. The corrections from Note 1497003 are a prerequisite for implementing this note.
Logical File Names: FI_DME_DOWNLOAD_PATH, FI_DME_DOWNLOAD_FILE (Programs: Transaction FDTA); FI_DME_CREATE_PATH, FI_DME_CREATE_FILE (Programs: SAPFPAYM, RFFOD__L, RFFOD__U, RFFOD__Z).
If you do not want to check the file name and path, you do not have to take any action. If you want to carry out a check, in transaction FILE, define an actual path or actual file name for the above logical file names and logical path names.
Note: If the check fails, no payment medium file is created either. If the check fails in transaction FDTA, the system issues an information message and the file is not downloaded.
After you implement the corrections from this note, implement the corrections from Note 1538366 also. The corrections do not contain the logical file names and paths.
Reason and prerequisites
1. The programs listed in the correction instructions contain a vulnerability that a malicious user could use to read any files, potentially containing confidential data, on a remote server.
2. Some of the programs listed in the correction instructions contain a vulnerability that a malicious user could use to overwrite any files on a remote server in order to potentially destroy data or to change the system response.
Side effects
Causes side effects in 1538366 – Update 1 to Security Note 1511617.
CVSS
Score 0
References
Affected components
- SAP_APPL: 31I, 40B, 45B, 46B, 46C, 470, 500, 600, 602, 603, 604, 605
Full note on SAP: SAP Support Launchpad note 1511617
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
