SAP security note 1540257, "Potential directory traversal in bill of exchange trans.". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Potential directory traversal in bill of exchange transactions.
Solution
For detailed information and instructions, refer to Note 1497003. Implementing the corrections from Note 1497003 is a prerequisite for applying this note.
Reason and prerequisites
The programs specified in the correction instructions contain vulnerabilities that allow a malicious user to potentially read arbitrary files on the remote server, possibly disclosing confidential information. Additionally, some programs allow writing arbitrary files, which can lead to data corruption or alteration of system behavior.
Affected components
- Financial Accounting > Accounts Receivable > Basic Functions > Bill of exchange (FI-AR-AR-H)
Full note on SAP: SAP Support Launchpad note 1540257
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
