SAP security note 1578477, "Directory Traversal in Code Page Converter Tools", is a program error note released on 12.07.2011. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Code page converter tools contain a vulnerability through which a malicious user can potentially write arbitrary files on the remote server, possibly corrupting data or altering system behavior.
Solution
Please apply the support package mentioned in this note at least, or the respective correction instruction.
Reason and prerequisites
Code page converter tools fail to correctly validate the path to which a user-submitted file is written. As a result, a malicious user can potentially overwrite data in the remote system.
References
- 1600307 – RSCP0013 fails when it calls RSCP0002
- 1411585 – Obsolete text in RSCPINST with some logon languages
Affected components
- SAP_BASIS
Full note on SAP: SAP Support Launchpad note 1578477
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




