SAP security note 1602943, "FI-CA Potential directory traversal", addresses a security vulnerability affecting SAP systems. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Potential directory traversal in the following components: FI-CA.
Solution
- Implement the Correction Instruction: download and apply the correction instruction (Download for SNOTE).
- Refer to Prerequisite Notes: ensure that you have implemented the corrections from Note 1497003 as they are prerequisites for this note.
Logical file names used in this solution: FI-CA-CVS.
Recommendations for setting up logical file names: to avoid maintaining a high number of logical file names, some programs share the same logical file name. This creates dependencies among these programs. Securely separate data created by different users and programs by creating a directory structure that reflects the user name and/or program name. Use this structured information when setting up the physical path and file names for the logical file paths and file names.
Reason and prerequisites
The programs contained in the correction instructions have vulnerabilities that allow a malicious user to potentially:
- Read arbitrary files on the remote server, possibly disclosing confidential information.
- Write arbitrary files on the remote server, possibly corrupting data or altering system behavior.
References
- Note 1589424: Directory traversal in FI-CA
- Note 1507122: FI-CA Potential Directory Traversal
- Note 1497003: Potential directory traversals in applications
Affected components
- FI-CA versions 471, 472, 600, 602, 603, 604, 605, 606, 616
Full note on SAP: SAP Support Launchpad note 1602943
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
