Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Obsolete programs in PSM-FG – Directory Traversal, SAP security note 1473165

SAP Note 1473165
SAP Security Note
High priority

SAP security note 1473165, “Obsolete programs in PSM-FG – Directory Traversal”, is a program error note released on 14.12.2010. Below are the symptom, SAP recommended solution and the affected software components.

ComponentPublic Sector Management > Federal Government Functions (PSM-FG)
CategoryProgram error
PriorityCorrection with high priority
TypeSAP Security Note
Version6
StatusReleased for Customer
Released on14.12.2010
LanguageEnglish

Description

Symptom

Potential Directory Traversal in the following components: PSM-FG.

Some programs within component PSM-FG contain vulnerabilities through which a malicious user can potentially read arbitrary files on the remote server, possibly disclosing confidential information.

Some of the programs within component PSM-FG contain a vulnerability through which a malicious user can potentially write arbitrary files on the remote server, possibly corrupting data or altering system behavior.

Solution

The affected programs are obsolete, so instead of doing extensive changes in the programs, the source code is commented out to prevent the programs from accessing confidential data.

Reason and prerequisites

Some programs within component PSM-FG fail to correctly validate the path a user-submitted file is read from or written to. Through this, an attacker can potentially point the program to an arbitrary other file on the system, disclosing its contents or overwriting data on the remote system.

References

Affected components

  • EA-PS 500
  • EA-PS 600
  • EA-PS 603
  • EA-PS 604
  • EA-PS 605

Full note on SAP: SAP Support Launchpad note 1473165

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More