Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

PT-FIAA Potential Directory Traversal, SAP security note 1909843

SAP Note 1909843
SAP Security Note
Medium priority

SAP security note 1909843, "PT-FIAA: Potential Directory Traversal", is a program error note released on June 7, 2016. Below are the symptom, SAP recommended solution and the affected software components.

ComponentMiscellaneous > Country/Region-Specific Developments > Portugal > use FI-LOC-AA-PT (XX-CSC-PT-FIAA)
CategoryProgram Error
PriorityMedium priority
TypeSAP Security Note
StatusReleased for Customer
Released onJune 7, 2016

Description

Symptom

Potential Directory Traversal in the component: XX-CSC-PT-FIAA.

Solution

  • Logical File Name: FIAA_RAIDPT02_NAME has been created to enable the validation of physical file names.
  • Logical File Path: FIAA_RAIDPT02_PATH is used for the above logical file name.

Action required: apply the attached correction instructions or upgrade to the latest support package.

Reason and prerequisites

  • Read Vulnerability: a malicious user can potentially read arbitrary files on the remote server, potentially disclosing confidential information.
  • Write Vulnerability: a malicious user can potentially write arbitrary files on the remote server, potentially corrupting data or altering system behavior.

Affected components

  • SAP_APPL (600 to 616)
  • SAP_FIN (617)

Full note on SAP: SAP Support Launchpad note 1909843

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More