Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

FIN-SEM Potential Directory Traversal, SAP security note 1501632

SAP Note 1501632High priority

SAP security note 1501632, "FIN-SEM: Potential Directory Traversal", is a program error note released on December 14, 2010. Below are the symptom, SAP recommended solution and the affected software components.

ComponentFinancials Basis (FIN-FB)
CategoryProgram error
PriorityCorrection with high priority
StatusReleased for Customer
Released onDecember 14, 2010
LanguageEnglish

Description

Symptom

A potential Directory Traversal vulnerability exists in the following component: FIN-SEM.

Solution

Refer to SAP Note 1497003 for additional information and instructions. The corrections from SAP Note 1497003 are a prerequisite for the implementation of this note.

  • Logical file name FIN_BASIS_UBC_BASIS: used in function group UBC_BAS_GEN, function modules UBC_FILE_UPLOAD and UBC_FILE_DELETE.
  • The logical file name FIN_BASIS_UBS_BASIS uses the logical file path FIN_BASIS_ROOT.

Reason and prerequisites

The programs included in the correction instructions contain vulnerabilities that allow a malicious user to potentially read arbitrary files on the remote server, which may disclose confidential information.

Some programs in the correction instructions allow a malicious user to potentially write arbitrary files on the remote server, possibly corrupting data or altering system behavior.

References

Affected components

  • FINBASIS versions 300, 600, 602, 603, 604, 605, 700

Full note on SAP: SAP Support Launchpad note 1501632

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More