Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

FI Potential Directory Traversal, SAP security note 1507211

SAP Note 1507211SAP Security NoteHigh priority

SAP security note 1507211, "FI: Potential Directory Traversal", is a program error note released on December 14, 2010. Below are the symptom, SAP recommended solution and the affected software components.

ComponentFI-AP-AP-Q1 (Financial Accounting > Accounts Payable > Basic Functions > Withholding Tax (Reporting))
CategoryProgram error
PriorityCorrection with high priority
TypeSAP Security Note
Version2
StatusReleased for Customer
Released onDecember 14, 2010
LanguageEnglish

Description

Symptom

Potential Directory Traversal in the following components:

  • FQST

Solution

Please refer to SAP Note 1497003 for additional information and instructions. The corrections from this note are a prerequisite for implementing this note.

Reason and prerequisites

The programs contained in the correction instructions contain vulnerabilities through which a malicious user can potentially read arbitrary files on the remote server, possibly disclosing confidential information. Some of the programs contained in the correction instructions contain a vulnerability through which a malicious user can potentially write arbitrary files on the remote server, possibly corrupting data or altering system behavior.

References

  • 1515184: Composite SAP Note: Security for FI-AR/FI-AP
  • 1497003: Potential directory traversals in applications

Affected components

  • SAP_APPL (Versions 31I, 40B, 45B, 46B, 46C, 470, 500, 600, 602, 603, 604, 605)

Full note on SAP: SAP Support Launchpad note 1507211

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More