SAP security note 1501632, "FIN-SEM: Potential Directory Traversal", is a program error note released on December 14, 2010. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
A potential Directory Traversal vulnerability exists in the following component: FIN-SEM.
Solution
Refer to SAP Note 1497003 for additional information and instructions. The corrections from SAP Note 1497003 are a prerequisite for the implementation of this note.
- Logical file name FIN_BASIS_UBC_BASIS: used in function group UBC_BAS_GEN, function modules UBC_FILE_UPLOAD and UBC_FILE_DELETE.
- The logical file name FIN_BASIS_UBS_BASIS uses the logical file path FIN_BASIS_ROOT.
Reason and prerequisites
The programs included in the correction instructions contain vulnerabilities that allow a malicious user to potentially read arbitrary files on the remote server, which may disclose confidential information.
Some programs in the correction instructions allow a malicious user to potentially write arbitrary files on the remote server, possibly corrupting data or altering system behavior.
References
Affected components
- FINBASIS versions 300, 600, 602, 603, 604, 605, 700
Full note on SAP: SAP Support Launchpad note 1501632
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
