SAP Security Note
High priority
SAP security note 1473165, “Obsolete programs in PSM-FG – Directory Traversal”, is a program error note released on 14.12.2010. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Potential Directory Traversal in the following components: PSM-FG.
Some programs within component PSM-FG contain vulnerabilities through which a malicious user can potentially read arbitrary files on the remote server, possibly disclosing confidential information.
Some of the programs within component PSM-FG contain a vulnerability through which a malicious user can potentially write arbitrary files on the remote server, possibly corrupting data or altering system behavior.
Solution
The affected programs are obsolete, so instead of doing extensive changes in the programs, the source code is commented out to prevent the programs from accessing confidential data.
Reason and prerequisites
Some programs within component PSM-FG fail to correctly validate the path a user-submitted file is read from or written to. Through this, an attacker can potentially point the program to an arbitrary other file on the system, disclosing its contents or overwriting data on the remote system.
References
This note refers to
Affected components
- EA-PS 500
- EA-PS 600
- EA-PS 603
- EA-PS 604
- EA-PS 605
Full note on SAP: SAP Support Launchpad note 1473165
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




