Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Restriction in access to FTP Servers & usage of test reports, SAP security note 1605054

SAP Note 1605054

SAP security note 1605054, "Restriction in access to FTP Servers & usage of test reports", is a note released on August 29, 2012. Below are the symptom, SAP recommended solution and the affected software components.

ComponentBC-SRV-COM-FTP
Released onAugust 29, 2012

Description

Symptom

FTP function modules previously allowed users to connect to any FTP Server without restrictions, posing a risk where malicious users could write arbitrary files, leading to data corruption or altered system behavior.

Solution

Implement the correction instructions provided in the note, followed by manual configuration to enforce FTP server restrictions and control access to FTP test reports.

  • Restrict FTP Test Reports Usage: assign the authority object S_ADMI_FCD with the field SFTP to users responsible for administrative or testing tasks. Refer to Note 1659034 if the SFTP field is unavailable during assignment.
  • Maintain FTP Server Whitelist: navigate to transaction SE16. Access the table SAPFTP_SERVERS. Create entries specifying the client, server name, and port to allow access. Alternatively, allow access to any FTP server by setting the server name to *.

CVSS

Score 5.5 Vector: AV:N/AC:L/AU:S/C:P/I:P/A:N

References

Affected components

  • SAP_BASIS: 46B, 46C, 620, 640, 700, 710, 711, 720, 730, 731

Full note on SAP: SAP Support Launchpad note 1605054

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More