Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

FI Potential Directory Traversal – Austria, SAP security note 1508378

SAP Note 1508378
SAP Security Note
High priority

SAP security note 1508378, "FI: Potential Directory Traversal – Austria", is a program error note released on 14.12.2010. Below are the symptom, SAP recommended solution and the affected software components.

ComponentXX-CSC-AT – Miscellaneous > Country/Region-Specific Developments > Austria
CategoryProgram error
PriorityCorrection with high priority
TypeSAP Security Note
Version2
StatusReleased for Customer
Released on14.12.2010
LanguageEnglish

Description

Symptom

Potential Directory Traversal in the following components:

  • XX-CSC-AT

Solution

Please refer to note 1497003 for additional information and instructions. The corrections from note 1497003 are a prerequisite for implementation of this note.

The following logical file names have been created in order to enable the validation of physical file names:

  • FI_RFASLD12_FILE – Program RFASLD12
  • FI_RFUVXX00_FILE – Program RFUVXX00
  • FI_RFIDATAFS_FILE – Program RFIDATAFS

All logical file names listed above use the logical file path FI_ERVJAB_FILE_PATH.

Reason and prerequisites

  • The programs contained in the correction instructions contain vulnerabilities through which a malicious user can potentially read arbitrary files on the remote server, possibly disclosing confidential information.
  • Some of the programs contained in the correction instructions contain a vulnerability through which a malicious user can potentially write arbitrary files on the remote server, possibly corrupting data or altering system behavior.

References

Affected components

  • SAP_APPL 31I
  • SAP_APPL 40B
  • SAP_APPL 45B
  • SAP_APPL 46A to 46B
  • SAP_APPL 46C
  • SAP_APPL 470
  • SAP_APPL 500
  • SAP_APPL 600
  • SAP_APPL 602
  • SAP_APPL 603
  • SAP_APPL 604
  • SAP_APPL 605

Full note on SAP: SAP Support Launchpad note 1508378

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More