Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Directory traversal in /CCEE/SIFI_RFASLM00_SI, SAP security note 1961993

SAP Note 1961993
SAP Security Note
Medium priority

SAP security note 1961993, "Directory traversal in /CCEE/SIFI_RFASLM00_SI", is a program error note released on 18.02.2014. Below are the symptom, reason and prerequisites, SAP recommended solution and related references.

ComponentMiscellaneous > Country/Region-Specific Developments > Slovenia > use FI-LOC-FI-SI (XX-CSC-SI-FI)
CategoryProgram error
PriorityMedium priority
TypeSAP Security Note
Version1
StatusReleased for Customer
Released on18.02.2014
LanguageEnglish

Description

Symptom

/CCEE/SIFI_RFASLM00_SI contains a vulnerability that allows an attacker to potentially write arbitrary files to the remote server, which could corrupt data or alter system behavior.

Solution

  • Support Package Installation: apply the relevant Support Package as outlined by SAP.
  • Manual Corrections: follow the instructions in the attachment.
  • Use Transaction SNOTE: apply code corrections using transaction SNOTE.
  • Prerequisite Note: ensure that Note 1497003 is implemented before applying this note.

Reason and prerequisites

The path validation in /CCEE/SIFI_RFASLM00_SI is inadequate, enabling attackers to overwrite data on the remote system.

References

Full note on SAP: SAP Support Launchpad note 1961993

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More