SAP security note 1509794, "Directory Traversal in transactions CL6E and CL6F". Below are the symptom and the SAP recommended solution.
Description
Symptom
Transactions CL6E and CL6F contain a vulnerability that allows a malicious user to potentially read arbitrary files on the remote server, potentially disclosing confidential information.
Solution
- Ensure that the corrections contained in Note 1512352 are implemented in your system.
- Follow the correction instructions provided in this note as per the advance correction guidelines.
- Refer to Note 1497003 for additional information. Program changes from this note are also required as a prerequisite.
- Logical file names have been created to validate physical file names:
DIN_CLASSfor transaction CL6E (logical path nameDIN_CLASS_PATH), andDIN_CHARACTERISTICfor transaction CL6F (logical path nameDIN_CHARACTERISTIC_PATH).
Reason and prerequisites
Transactions CL6E and CL6F fail to correctly validate the path used to reference a file read from the remote server. This vulnerability allows an attacker to point the program to an arbitrary file on the system, disclosing its contents.
CVSS
Score 0
References
This note refers to
- 1514017 – Directory Traversal in transactions CL6E and CL6F
- 1512352 – Directory Traversal in batch input reports in class system
- 1510773 – Directory Traversal in RFC modules in classification
- 1509235 – Directory Traversal in RFC modules in classification
- 1497003 – Potential directory traversals in applications
Full note on SAP: SAP Support Launchpad note 1509794
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
