SAP Security Note
Medium priority
SAP security note 1909843, "PT-FIAA: Potential Directory Traversal", is a program error note released on June 7, 2016. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Potential Directory Traversal in the component: XX-CSC-PT-FIAA.
Solution
- Logical File Name:
FIAA_RAIDPT02_NAMEhas been created to enable the validation of physical file names. - Logical File Path:
FIAA_RAIDPT02_PATHis used for the above logical file name.
Action required: apply the attached correction instructions or upgrade to the latest support package.
Reason and prerequisites
- Read Vulnerability: a malicious user can potentially read arbitrary files on the remote server, potentially disclosing confidential information.
- Write Vulnerability: a malicious user can potentially write arbitrary files on the remote server, potentially corrupting data or altering system behavior.
Affected components
- SAP_APPL (600 to 616)
- SAP_FIN (617)
Full note on SAP: SAP Support Launchpad note 1909843
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




