SAP security note 1510789, “Travel Expenses: Potential directory traversal”. Below are the symptom, the SAP recommended solution, CVSS and references.
Description
Symptom
Travel expenses management fails to correctly validate the path to which a user-submitted file is written. As a result, a malicious user can potentially overwrite data in the remote system.
Solution
See Note 1497003 for more information. The corrections from Note 1497003 are a prerequisite for this note.
This note creates the following logical file names to check the physical file names:
- FI_TV_RPRCCC00_FILE
- Programs: RPRCCC00 "Import of Credit Card Data (Credit Card Clearing)", RPRCCC_CREATE_TESTFILE "Create a test file for credit card clearing", RPRCCC_CREATE_CORRECTION_FILE
- Logical Path: FI_TV_CCC_FILES
- FI_TV_RPRIRB00_30_FILE
- Programs: RPRIRB00_30, RPRC50R3
- Logical Path: FI_TV_POSTING_RUN_FILES
- FI_TV_RPRFIN00_30_FILE
- Programs: RPRFIN00_30, RPREPR3C
- Logical Path: FI_TV_POSTING_RUN_FILES
- FI_TV_CCC_AMEX_FILE
- Programs: RPRCCC_READ_BTA, RPRCCC_READ_KR1025
- Parameters: <PARAM_1> The "Company ID" field of the selection screen
- Logical Path: FI_TV_CCC_AMEX_FILES
- FI_TV_RPRTAX_FILE
- Programs: RPRTAX_FINLAND
- Logical Path: FI_TV_RPRTAX_FILES
CVSS
Score 0
References
- 1507935 – HCM: Potential Directory Traversal Internat. Payroll PY-XX
- 1497003 – Potential directory traversals in applications
Full note on SAP: SAP Support Launchpad note 1510789
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
