SAP Security Note
High priority
SAP security note 1552798, "Directory Traversal in EH&S", was released on October 11, 2011. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
- Implementation of SAP Note 1505368: EHS – Potential Directory Traversal (EHS: Potential Directory Traversal).
- Importing inbound documents using transaction
CG36terminates with the error:Internal program error; (RC1IMPPG SAPLC13Z 1 C13Z_RAWDATA_WRITE) (C$ 153)
Solution
To address this vulnerability, apply the relevant support packages listed below or follow the provided correction instructions.
Reason and prerequisites
EH&S exhibits an error when checking the file storage path, allowing a malicious user to overwrite data on the remote system.
References
- SAP Note 1505368: EHS – Potential Directory Traversal
- SAP Note 1540408: Update #1 for security Note 1505368
Affected components
- EA-APPL: 110, 200, 500, 600, 602, 603, 604, 605
- EHS: 0207B0406C
Full note on SAP: SAP Support Launchpad note 1552798
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




