SAP Security Note
High priority
SAP security note 1526753, “FI: Potential Directory Traversal-Additional Corrections”, released on December 14, 2010. Below are the symptom and SAP recommended solution.
Description
Symptom
This note addresses critical vulnerabilities related to potential directory traversal in the Financial Accounting component, specifically in FI-AP-AP-B1 (Financial Accounting > Accounts Payable > Basic Functions > Payment transfer (w/o DE, US)).
- Directory Traversal: Allows malicious users to read arbitrary files on the server, potentially exposing confidential information.
- Arbitrary File Writing: Enables attackers to write arbitrary files on the server, which can lead to data corruption or alteration of system behavior.
Solution
This note provides additional correction instructions to mitigate the identified vulnerabilities. It is essential to apply these corrections after implementing Note 1506843 to ensure comprehensive protection.
Reason and prerequisites
Before applying this note, ensure that Note 1506843 is applied, as this note provides foundational security enhancements that are built upon by Note 1526753.
References
Full note on SAP: SAP Support Launchpad note 1526753
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



