Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Directory Traversal in transactions CL6E and CL6F, SAP security note 1509794

SAP Note 1509794

SAP security note 1509794, "Directory Traversal in transactions CL6E and CL6F". Below are the symptom and the SAP recommended solution.

Description

Symptom

Transactions CL6E and CL6F contain a vulnerability that allows a malicious user to potentially read arbitrary files on the remote server, potentially disclosing confidential information.

Solution

  • Ensure that the corrections contained in Note 1512352 are implemented in your system.
  • Follow the correction instructions provided in this note as per the advance correction guidelines.
  • Refer to Note 1497003 for additional information. Program changes from this note are also required as a prerequisite.
  • Logical file names have been created to validate physical file names: DIN_CLASS for transaction CL6E (logical path name DIN_CLASS_PATH), and DIN_CHARACTERISTIC for transaction CL6F (logical path name DIN_CHARACTERISTIC_PATH).

Reason and prerequisites

Transactions CL6E and CL6F fail to correctly validate the path used to reference a file read from the remote server. This vulnerability allows an attacker to point the program to an arbitrary file on the system, disclosing its contents.

CVSS

Score 0

References

Full note on SAP: SAP Support Launchpad note 1509794

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More