Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

FI-CA Potential directory traversal, SAP security note 1602943

SAP Note 1602943

SAP security note 1602943, "FI-CA Potential directory traversal", addresses a security vulnerability affecting SAP systems. Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

Potential directory traversal in the following components: FI-CA.

Solution

  1. Implement the Correction Instruction: download and apply the correction instruction (Download for SNOTE).
  2. Refer to Prerequisite Notes: ensure that you have implemented the corrections from Note 1497003 as they are prerequisites for this note.

Logical file names used in this solution: FI-CA-CVS.

Recommendations for setting up logical file names: to avoid maintaining a high number of logical file names, some programs share the same logical file name. This creates dependencies among these programs. Securely separate data created by different users and programs by creating a directory structure that reflects the user name and/or program name. Use this structured information when setting up the physical path and file names for the logical file paths and file names.

Reason and prerequisites

The programs contained in the correction instructions have vulnerabilities that allow a malicious user to potentially:

  • Read arbitrary files on the remote server, possibly disclosing confidential information.
  • Write arbitrary files on the remote server, possibly corrupting data or altering system behavior.

References

Affected components

  • FI-CA versions 471, 472, 600, 602, 603, 604, 605, 606, 616

Full note on SAP: SAP Support Launchpad note 1602943

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More