Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Potential directory traversals in transaction TVDT, SAP security note 1509403

SAP Note 1509403SAP Security Note

SAP security note 1509403, "Potential directory traversals in transaction TVDT", is a note released on August 16, 2011. Below are the symptom and SAP recommended solution.

ComponentFinancial Supply Chain Management > Treasury and Risk Management > Market Risk Analyzer (FIN-FSCM-TRM-MR)
TypeSAP Security Note
Version8
Released onAugust 16, 2011

Description

Symptom

Potential directory traversals in transactions TVDT using physical file names as input.

Solution

Refer to Note 1497003 for additional information and instructions. The corrections from Note 1497003 are a prerequisite for implementing this note.

Reason and prerequisites

The programs contained in the correction instructions have vulnerabilities that allow a malicious user to potentially read arbitrary files on the remote server, possibly disclosing confidential information.

Some programs contain vulnerabilities that allow a malicious user to potentially write arbitrary files on the remote server, possibly corrupting data or altering system behavior.

References

Full note on SAP: SAP Support Launchpad note 1509403

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More