SAP Security Note
Medium priority
SAP security note 1521084, "Potential Directory Traversal for report RSTEXTA3", is a program error note released on December 14, 2010. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Potential Directory Traversal in report RSTEXTA3.
Solution
Please refer to SAP Note 1497003 for additional information and instructions. The corrections from SAP Note 1497003 are a prerequisite for implementing this note.
The following logical file name has been created to enable the validation of physical file names: BC_RSTEXTA3 (software component SAP_BASIS, logical file path TRANSLATION), used by program RSTEXTA3.
Reason and prerequisites
Report RSTEXTA3 contains a vulnerability that allows a malicious user to potentially write arbitrary files on the remote server, which may lead to data corruption or altered system behavior.
CVSS
Score 0
References
- SAP Note 1573997 – Potential Directory Traversal in Translation Tools
- SAP Note 1520295 – File names in the report RSTEXTA3
- SAP Note 1497003 – Potential directory traversals in applications
Affected components
- SAP_BASIS: 610 to 640
- SAP_BASIS: 700 to 702
- SAP_BASIS: 710 to 730
Full note on SAP: SAP Support Launchpad note 1521084
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



