Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

FI Potential Directory Traversal- Italy(RFIDITVCL), SAP security note 1698242

SAP Note 1698242
SAP Security Note
High priority

SAP security note 1698242, "FI: Potential Directory Traversal- Italy(RFIDITVCL)", is a program error note released on 11.09.2012. Below are the symptom and SAP recommended solution.

ComponentFinancial Accounting > General Ledger Accounting > Basic Functions > Deferred Tax (Country Specific)
CategoryProgram error
PriorityCorrection with high priority
TypeSAP Security Note
Version1
StatusReleased for Customer
Released on11.09.2012
LanguageEnglish

Description

Symptom

Potential Directory Traversal for RFIDITVCL.

Solution

Please refer to note 1497003 for additional information and instructions. The corrections from note 1497003 are a prerequisite for implementation of this note.

Logical File Name Used in this Solution: the following logical file names have been created in order to enable the validation of physical file names: FI_RFIDITVCL_FILE. Program Using this Logical Filename: RFIDITVCL.

Logical File Path Used in this Solution: FI_ITVCL_FILE_PATH.

The application RFIDITVCL is passing an additional parameter parameter_1 (sy-cprog) to the Function Module FILE_VALIDATE_NAME. This will allow a customer to insert the parameter while configuring the physical paths for the Logical File Name FI_RFIDITVCL_FILE.

Reason and prerequisites

  • The programs contained in the correction instructions contain vulnerabilities through which a malicious user can potentially read arbitrary files on the remote server, possibly disclosing confidential information.
  • Some of the programs contained in the correction instructions contain a vulnerability through which a malicious user can potentially write arbitrary files on the remote server, possibly corrupting data or altering system behavior.

References

  • 1497003 – Potential directory traversals in applications

Full note on SAP: SAP Support Launchpad note 1698242

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More