Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Update #1 for Security Note 1512352, SAP security note 1555924

SAP Note 1555924
SAP Security Note
High priority

SAP security note 1555924, "Update #1 for Security Note 1512352", is a program error note released on 13.09.2011. Below are the symptom, SAP recommended solution and the affected software components.

ComponentCross-Application Components > Classification
CategoryProgram error
PriorityCorrection with high priority
TypeSAP Security Note
Version2
StatusReleased for Customer
Released on13.09.2011
LanguageEnglish

Description

Symptom

Correction instructions for the directory traversal vulnerability described in Security Note 1512352 must be corrected for all releases. The corrected correction instructions have been added to this note.

Even though you have maintained Customizing for the logical file names for the input file and output file of the report RCCLBI03, the physical file names that are assigned are not identified as valid.

Solution

Implement the correction instructions.

If you have not yet implemented Note 1512352, it is implemented automatically as a required note.

If you want to store the output file on the application server, use the logical file name CLASSIFICATION_ERROR. The name defines the path under which the output file is saved. The system suggests RCCLBI03.ERROR as the file name, but you can choose your own file name. The path is not specified either on the presentation server. Here, CLASSIFICATION_ERROR (if defined) represents a default value.

CLASSIFICATION_ERROR must also be defined in Customizing.

Reason and prerequisites

Security Note 1512352 contains correction instructions that are incorrect and require a correction.

References

Affected components

  • SAP_APPL: 31I, 40B, 45B, 46B, 46C
  • SAP_ABA: 620, 640, 700 to 702, 710 to 711, 730

Full note on SAP: SAP Support Launchpad note 1555924

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More