Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Directory traversal in /CCEE/RSFI_EXPORT_GL_LINE, SAP security note 1961949

SAP Note 1961949

SAP security note 1961949, "Directory Traversal Vulnerability in /CCEE/RSFI_EXPORT_GL_LINE". Below are the symptom, reason and prerequisites, SAP recommended solution and the affected software components.

ComponentC-CEE

Description

Symptom

A directory traversal vulnerability has been identified in /CCEE/RSFI_EXPORT_GL_LINE, allowing an attacker to write arbitrary files to the remote server. This could lead to data corruption or alteration of system behavior.

Solution

To address this vulnerability, follow these steps:

  • Apply manual corrections as provided in the attachment.
  • Apply code corrections using the Note Assistant (SNOTE).
  • Ensure that Note 1497003 is applied before implementing this note, as it is a prerequisite.

Reason and prerequisites

An attacker exploiting this vulnerability can overwrite data on the remote system by manipulating the file path validation in the affected component, potentially leading to unauthorized data modification or disruption of services.

Affected components

  • C-CEE 110_600
  • C-CEE 110_602
  • C-CEE 110_603
  • C-CEE 110_604

Full note on SAP: SAP Support Launchpad note 1961949

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More