Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

SLL-LEG-FUN-UPL Directory Traversal, SAP security note 1571280

SAP Note 1571280
SAP Security Note
High priority

SAP security note 1571280, "SLL-LEG-FUN-UPL: Directory Traversal", is a program error note released on September 13, 2011. Below are the symptom and SAP recommended solution.

ComponentGlobal Trade Services / Logistics Services > Global Trade Services GTS > General Functions > GF: Upload
CategoryProgram error
PriorityCorrection with high priority
TypeSAP Security Note
Version2
StatusReleased for Customer
Released onSeptember 13, 2011
LanguageEnglish

Description

Symptom

Potential Directory Traversal in the following component: SLL-LEG-FUN-UPL.

Solution

To mitigate these vulnerabilities, please refer to SAP Note 1497003 for additional information and instructions. Implementing the corrections from both Note 1497003 and Note 1556515 is a prerequisite for applying this security note.

The following logical file name and path have been created to validate physical file names and paths: Logical File Name: SLL_LEG_FUN_UPL; Logical File Path: SLL_LEG_FUN_UPL; Program Using This Logical File Name: /SAPSLL/MARC_UPLOAD_R3; Parameters Used: <PARAM_1> Program name.

Reason and prerequisites

Read Vulnerability. The program included in the correction instruction contains vulnerabilities that allow a malicious user to read arbitrary files on the remote server, potentially disclosing confidential information.

Write Vulnerability. Some programs in the correction instructions enable a malicious user to write arbitrary files on the remote server, possibly leading to data corruption or altered system behavior.

References

Full note on SAP: SAP Support Launchpad note 1571280

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More