SAP security note 1584421, "FI-CA Potential Directory Traversal", is a note. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
A potential Directory Traversal vulnerability has been identified in the SAP FI-CA component. This vulnerability allows malicious users to read or write arbitrary files on the remote server, which could lead to the disclosure of confidential information, data corruption, or altered system behavior.
Solution
- Implement the Correction Instructions: Apply the correction instructions provided in SAP Note 1584421.
- Refer to Prerequisite Notes: Ensure that Note 1497003 and Note 1509883 are implemented before applying this note.
Reason and prerequisites
The vulnerability exists due to insufficient validation in the programs included in the correction instructions. This lack of proper validation can be exploited to perform directory traversal attacks.
References
- SAP Note 1584976 – FS-CD: Potential Directory Traversal
- SAP Note 1497003 – Potential directory traversals in applications
Affected components
- FI-CA 451
- FI-CA 461
- FI-CA 464
- FI-CA 471
- FI-CA 472
- FI-CA 600
- FI-CA 602
- FI-CA 603
- FI-CA 604
- FI-CA 605
Full note on SAP: SAP Support Launchpad note 1584421
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
