SAP Security Note
High priority
SAP security note 1504446, "Directory Traversal in the RCCF engines", is a program error note released on December 14, 2010. Below are the symptom and SAP recommended solution.
Description
Symptom
The Remote Control and Communication Framework (RCCF) contains a vulnerability that allows a malicious user to write arbitrary files on the remote server. This can potentially corrupt data or alter system behavior.
Solution
To address this vulnerability, you have two options:
- Update support packages: import SAP_BS_FND 7.01 Support Package 08, or import SAP_BS_FND 7.02 Support Package 03.
- Implement source code corrections: follow the correction instructions provided in this note.
Reason and prerequisites
The RCCF does not correctly validate the path where a user-submitted file is written. This oversight allows an attacker to overwrite data on the remote system.
Full note on SAP: SAP Support Launchpad note 1504446
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



