Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Potential directory traversals in batch input programs, SAP security note 1509179

SAP Note 1509179
SAP Security Note
High priority

SAP security note 1509179, "Potential directory traversals in batch input programs", was released on 14.12.2010. Below are the symptom and SAP recommended solution.

ComponentIndustry-Specific Components > Bank (IS-B)
PriorityCorrection with high priority
TypeSAP Security Note
Version3
StatusReleased for Customer
Released on14.12.2010

Description

Symptom

Potential directory traversals in batch input programs RJBDBTC3, RJBDBTC2, RJBDBTC1, MJBEHF01.

Solution

Please refer to Note 1497003 for additional information and instructions. The corrections from this note are a prerequisite for the implementation of this note.

Logical file names used in this solution:

  • RJBDBTC3 (Batch Input for Derivatives): FTRM_AN_BATCH_INPUT_DER – Treasury: input file path/name for Batch input for Derivatives
  • RJBDBTC2 (Batch Input for Money Market): FTRM_AN_BATCH_INPUT_MM – Treasury: input file path/name for Batch input for Money Market
  • RJBDBTC1 (Batch Input for Forex): FTRM_AN_BATCH_INPUT_FX – Treasury: input file path/name for Batch input for Forex
  • MJBEHF01 (Include): FTRM_AN_BATCH_INPUT_ERR_FILE – Treasury: error file path/name for Batch input

Reason and prerequisites

  • The programs contained in the correction instructions contain vulnerabilities through which a malicious user can potentially read arbitrary files on the remote server, possibly disclosing confidential information.
  • Some of the programs contained in the correction instructions contain a vulnerability through which a malicious user can potentially write arbitrary files on the remote server, possibly corrupting data or altering system behavior.

References

Full note on SAP: SAP Support Launchpad note 1509179

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More