SAP security note 1532960, "Funding Management: Potential directory traversals". Below are the symptom and SAP recommended solution.
Description
Symptom
The default implementation of the BAdI for securitization (import and export of offers, sales, and portfolios) in Funding Management permits the reading or writing of arbitrary files to the application server.
Solution
Implement the attached correction instructions or import the relevant Support Package. Note that the corrections provided in Note 1497003 are a prerequisite for implementing this note. If you apply the corrections from this note without those from Note 1497003, the relevant functions remain active, and file names are not validated.
When implementing the corrections from this note, logical file names and file paths are introduced to validate the input data. System administration must adjust the specific physical file paths according to requirements.
Reason and prerequisites
A gap in the program design within the attached correction instructions allows a user to read arbitrary files on the network, leading to unauthorized access to confidential information. Additionally, another design gap permits the writing of arbitrary files on the network, posing a security risk. For more details, refer to Note 1497003.
References
Full note on SAP: SAP Support Launchpad note 1532960
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
