SAP Security Note
High priority
SAP security note 1597062, "FI: Potential Directory Traversal-Spain", is a program error note released on 08.11.2011. Below are the symptom and SAP recommended solution.
Description
Symptom
Potential Directory Traversal for RFIDESM340.
Solution
Please refer to Note 1497003 for additional information and instructions. The corrections from Note 1497003 are a prerequisite for implementation of this note.
Logical File Name Used in this Solution: the following logical file names have been created to enable the validation of physical file names: FI_RFIDESM340_FILE
Program Using this Logical Filename: RFIDESM340
Logical File Path Used in this Solution: FI_M340_FILE_PATH
The application RFIDESM340 is passing an additional parameter parameter_1 (sy-cprog) to the Function Module FILE_VALIDATE_NAME. This allows customers to insert the parameter while configuring the physical paths for the Logical File Name FI_RFIDESM340_FILE.
Reason and prerequisites
The programs contained in the correction instructions contain vulnerabilities through which a malicious user can potentially read arbitrary files on the remote server, possibly disclosing confidential information. Some of the programs contained in the correction instructions contain a vulnerability through which a malicious user can potentially write arbitrary files on the remote server, possibly corrupting data or altering system behavior.
References
Full note on SAP: SAP Support Launchpad note 1597062
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
