SAP Security Note
High priority
SAP security note 1519061, "IS-H AT: Directory Traversal in various reports", was released on 13.10.2011. Below are the symptom and the SAP recommended solution.
Description
Symptom
This security note addresses a directory traversal vulnerability in several IS-H AT (Industry-Specific Components for Hospital in Austria) reports. A malicious user could exploit this vulnerability to read or write arbitrary files on the remote server, potentially corrupting data or altering system behavior.
Affected programs: RNWATICD10, RNWATMELMAP, RNWATSCO50, RNWAT_SCO_MSG_LOAD, and, in IS-H Version 6.05, RNUEZG50, RNUICD50, RNUPLZ50, RNWATSTERNKR_LOAD.
Solution
Implement the corrections from SAP Note 1497003 first.
Then, in transaction FILE, open "Logical File Path Definition, Cross-Client" and create new entries for each affected report: set the logical file to the report name, the name to "Validation for <REPORT NAME>", the data format to DIR, and the application area to IS. Repeat for each report and save.
Reports to update: RNWATICD10, RNWATMELMAP, RNWATSCO50, RNWAT_SCO_MSG_LOAD.
References
- SAP Note 1526102 – IS-H: Directory Traversal Vulnerability in IS-H
- SAP Note 1510407 – IS-H: Directory Traversal Vulnerability in IS-H
- SAP Note 1497003 – Potential directory traversals in applications
Full note on SAP: SAP Support Launchpad note 1519061
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
