SAP security note 1529573, "Directory Traversal in Bank Analyzer Correction Server". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
The Bank Analyzer Correction Server contains a vulnerability that allows a malicious user to perform directory traversal, leading to the possibility of writing arbitrary files on the remote server.
Solution
Implement the attached correction provided in the SAP Note. This correction removes the option to enter a specific application or presentation server file name on the selection screen. However, the options to execute and print (or send to a file) and to display online and save the ALV display to a file remain available and are unaffected by this correction.
Reason and prerequisites
The vulnerability arises because the Bank Analyzer Correction Server fails to correctly validate the path where a user-submitted file is written. This oversight allows an attacker to potentially overwrite data on the remote system.
CVSS
Score 0
References
This note refers to
Affected components
- FSAPPL 200
- FSAPPL 300
- BANK-ALYZE 42
- BANK-ALYZE 50
Full note on SAP: SAP Support Launchpad note 1529573
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
