SAP security note 1587531, "Directory Traversal in class system reports". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
A vulnerability exists in the classification reports (RCCLUKA2 and RMCLTEXT) that allows a malicious user to perform directory traversal. This can enable the writing of arbitrary files on the remote server, potentially leading to data corruption or alteration of system behavior.
Solution
- Implement Advance Correction: Follow the correction instructions as outlined in the note.
- Define Logical File Names: Use transaction FILE to define the following logical file names if they are not already available: CLASS_TEXT for report RMCLTEXT; RCCLUKA2_KSSK and RCCLUKA2_AUSP for report RCCLUKA2.
- Assign Physical File Names: Enter the physical paths for the logical file names in transaction SF01.
- Reference Prerequisite Note: Apply Note 1497003 as it is a prerequisite for this security note.
Affected components
- SAP_APPL 31I to 46C
- SAP_ABA 620 to 730
Full note on SAP: SAP Support Launchpad note 1587531
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
