Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Potential directory traversals /CCEE/SIFI_EXPORT_GL_LINE, SAP security note 1531793

SAP Note 1531793
SAP Security Note
High priority

SAP security note 1531793, "Potential directory traversals /CCEE/SIFI_EXPORT_GL_LINE", is a program error note released on 14.12.2010. Below are the symptom, SAP recommended solution and the affected software components.

ComponentMiscellaneous > Country/Region-Specific Developments > Slovenia > use FI-LOC-FI-SI
CategoryProgram error
PriorityCorrection with high priority
TypeSAP Security Note
Version1
StatusReleased for Customer
Released on14.12.2010
LanguageEnglish

Description

Symptom

Potential Directory Traversal in the following components: C-CEE, Report: /CCEE/SIFI_EXPORT_GL_LINE.

Solution

Please refer to Note 1497003 for additional information and instructions. The corrections from note 1497003 are a prerequisite for implementing this note.

Reason and prerequisites

The programs contained in the correction instructions have vulnerabilities that allow a malicious user to potentially read arbitrary files on the remote server, potentially disclosing confidential information.

Some programs in the correction instructions contain vulnerabilities that allow a malicious user to potentially write arbitrary files on the remote server, possibly corrupting data or altering system behavior.

References

Affected components

  • C-CEE: Versions 011_46C to 110_604

Full note on SAP: SAP Support Launchpad note 1531793

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More