SAP security note 1961949, "Directory Traversal Vulnerability in /CCEE/RSFI_EXPORT_GL_LINE". Below are the symptom, reason and prerequisites, SAP recommended solution and the affected software components.
Description
Symptom
A directory traversal vulnerability has been identified in /CCEE/RSFI_EXPORT_GL_LINE, allowing an attacker to write arbitrary files to the remote server. This could lead to data corruption or alteration of system behavior.
Solution
To address this vulnerability, follow these steps:
- Apply manual corrections as provided in the attachment.
- Apply code corrections using the Note Assistant (SNOTE).
- Ensure that Note 1497003 is applied before implementing this note, as it is a prerequisite.
Reason and prerequisites
An attacker exploiting this vulnerability can overwrite data on the remote system by manipulating the file path validation in the affected component, potentially leading to unauthorized data modification or disruption of services.
Affected components
- C-CEE 110_600
- C-CEE 110_602
- C-CEE 110_603
- C-CEE 110_604
Full note on SAP: SAP Support Launchpad note 1961949
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




