SAP security note 1591040, "Security Verdict in SAUD RSGENLOAD", is a note released on 08.11.2011. Below are the symptom and SAP recommended solution.
Description
Symptom
A program in Package SAUD contains a vulnerability through which a malicious user can potentially read arbitrary files on the remote server, possibly impacting the system behaviour.
Solution
Implement this Note or apply the corresponding Support Package.
Reason and prerequisites
The program fails to correctly validate the path that is used to reference a file that is read from the remote server. The content is copied into an internal table which then triggers report load generation. As a result, a malicious user with sufficient authorization to execute programs can direct the program to an arbitrary other file in the system, with possible negative impact on the system behaviour.
Full note on SAP: SAP Support Launchpad note 1591040
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



