Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CML Potential Directory Traversal, SAP security note 1506736

SAP Note 1506736SAP Security NoteHigh priority

SAP security note 1506736, "CML: Potential Directory Traversal", is a program error note released on December 14, 2010. Below are the symptom, SAP recommended solution and the affected software components.

CategoryProgram error
PriorityCorrection with high priority
TypeSAP Security Note
StatusReleased for Customer
Released onDecember 14, 2010
LanguageEnglish

Description

Symptom

FS-CML (US specific payment processing) contains a vulnerability that allows a malicious user to potentially write arbitrary files on the remote server. This could lead to data corruption or alteration of system behavior.

Solution

Refer to SAP Note 1497003 for additional information and instructions. Implementing the corrections from this note is a prerequisite for applying the fixes in SAP Note 1506736.

Programs using the logical file names:

  • CML_PAYMENT_US: RFVD_AUTODRAFT_PROCESS, RFVD_PAY_STOP
  • CML_CREDIT_BUREAU: RFVD_CBR_PROCESS

Logical file path used: CML_ROOT.

References

Affected components

  • EA-FINSERV: 600, 603, 604, 605

Full note on SAP: SAP Support Launchpad note 1506736

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More