SAP security note 1507122, "FI-CA Potential Directory Traversal". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Potential Directory Traversal in the component FI-CA.
Solution
Please refer to SAP Note 1497003 for additional information and instructions. The corrections from SAP Note 1497003 are a prerequisite for implementing this note.
Reason and prerequisites
The programs contained in the correction instructions have vulnerabilities that allow a malicious user to potentially read arbitrary files on the remote server, possibly disclosing confidential information. Additionally, some programs may allow a malicious user to write arbitrary files on the remote server, potentially corrupting data or altering system behavior.
Affected components
- Industry-Specific Components > Utilities (IS-U)
- Industry-Specific Components > Public Sector Solutions > Public Sector Contract Accounting (IS-PS-CA)
- Industry-Specific Components > Media (IS-M)
- Industry-Specific Components > Media > Contract Accounts Receivable and Payable (IS-M-CA)
- Industry-Specific Components > Industry-Specific Component Telecommunications > Contract Accounting (IS-T-CA)
- Industry-Specific Components > Industry-Specific Component Telecommunications (IS-T)
- Industry-Specific Components > Utilities > Contract Accounts Receivable and Payable (IS-U-CA)
- Financial Services > Collections and Disbursements (FS-CD)
- Financial Accounting > Non-industry specific contract accounts receivable, payable (FI-CAX)
- Financial Services > Collections and Disbursements > Reporting / Information System (FS-CD-IS)
Full note on SAP: SAP Support Launchpad note 1507122
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
