SAP security note 1953973, "Directory traversal in /CEECV/ROFI_VIES_394_XML". Below are the symptom, reason and prerequisites, SAP recommended solution and related references.
Description
Symptom
/CEECV/ROFI_VIES_394_XML contains a vulnerability that allows an attacker to potentially write arbitrary files to the remote server. This could lead to data corruption or alteration of system behavior.
Solution
SAP recommends installing solutions by applying a Support Package. If an earlier installation is necessary, follow these steps using the Note Assistant:
- Apply Manual Corrections: refer to the attachment for detailed instructions.
- Apply Code Correction Instructions: use transaction SNOTE to follow the instructions provided in this note.
- Install Prerequisite Note: apply Note 1497003. This note must be implemented before applying the current note.
To enhance security and reduce dependencies, create a directory structure that reflects the user name and/or program name, and use this structure when setting up physical paths and file names for logical file paths.
Reason and prerequisites
The path validation for user-submitted files in /CEECV/ROFI_VIES_394_XML is insufficient. As a result, an attacker can overwrite data on the remote system.
References
Full note on SAP: SAP Support Launchpad note 1953973
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



