Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Funding Management Potential directory traversals, SAP security note 1532960

SAP Note 1532960

SAP security note 1532960, "Funding Management: Potential directory traversals". Below are the symptom and SAP recommended solution.

Description

Symptom

The default implementation of the BAdI for securitization (import and export of offers, sales, and portfolios) in Funding Management permits the reading or writing of arbitrary files to the application server.

Solution

Implement the attached correction instructions or import the relevant Support Package. Note that the corrections provided in Note 1497003 are a prerequisite for implementing this note. If you apply the corrections from this note without those from Note 1497003, the relevant functions remain active, and file names are not validated.

When implementing the corrections from this note, logical file names and file paths are introduced to validate the input data. System administration must adjust the specific physical file paths according to requirements.

Reason and prerequisites

A gap in the program design within the attached correction instructions allows a user to read arbitrary files on the network, leading to unauthorized access to confidential information. Additionally, another design gap permits the writing of arbitrary files on the network, posing a security risk. For more details, refer to Note 1497003.

References

Full note on SAP: SAP Support Launchpad note 1532960

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More