Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

PSM Potential Directory Traversal, SAP security note 1504190

SAP Note 1504190
SAP Security Note
High priority

SAP security note 1504190, "PSM – Potential Directory Traversal", is a program error note released on December 14, 2010. Below are the symptom and SAP recommended solution.

ComponentPSM-FM (Public Sector Management > Funds Management)
CategoryProgram error
PriorityCorrection with high priority
TypeSAP Security Note
Version2
StatusReleased for Customer
Released onDecember 14, 2010
LanguageEnglish

Description

Symptom

SAP Security Note 1504190 addresses a potential directory traversal vulnerability in the Public Sector Management (PSM-FM) component. This issue allows a malicious user to potentially read or write arbitrary files on the remote server, which could lead to the disclosure of confidential information or corruption of data.

The vulnerability exists in the program contained within the correction instructions, which allows a malicious user to perform directory traversal attacks. Specifically:

  • Read arbitrary files: Potentially disclose confidential information by reading arbitrary files on the server.
  • Write arbitrary files: Potentially corrupt data or alter system behavior by writing arbitrary files on the server.

Solution

To address this vulnerability, refer to Note 1497003 for additional information and instructions. The corrections provided in Note 1497003 are prerequisites for the implementation of this note.

References

Full note on SAP: SAP Support Launchpad note 1504190

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More