SAP security note 1584976, "FS-CD: Potential Directory Traversal". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Potential Directory Traversal in the following component: FS-CD.
Solution
Please implement the attached correction instruction. Refer to SAP Note 1497003 for additional information and instructions. The corrections from SAP Note 1497003, SAP Note 1509883, and SAP Note 1584421 are prerequisites for the implementation of this note.
Reason and prerequisites
The programs contained in the correction instructions contain vulnerabilities through which a malicious user can potentially read arbitrary files on the remote server, possibly disclosing confidential information. Some of the programs contained in the correction instructions contain a vulnerability through which a malicious user can potentially write arbitrary files on the remote server, possibly corrupting data or altering system behavior.
References
- 1584421 – FI-CA Potential Directory Traversal
- 1509883 – FI-CA Data Transfer – Directory Traversal
- 1497003 – Potential Directory Traversals in Applications
Affected components
- INSURANCE
Full note on SAP: SAP Support Launchpad note 1584976
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
