Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Directory traversal in /CCEE/SIFI_RFEBBART00, SAP security note 1961994

SAP Note 1961994

SAP security note 1961994, "Directory Traversal Vulnerability in /CCEE/SIFI_RFEBBART00". Below are the symptom, SAP recommended solution and the affected software components.

ComponentC-CEE

Description

Symptom

SAP has released Security Note 1961994 addressing a critical directory traversal vulnerability in the /CCEE/SIFI_RFEBBART00 component. This vulnerability allows attackers to read and write arbitrary files on the remote server, potentially leading to the disclosure of confidential information or corruption of data.

Solution

SAP recommends applying the relevant Support Package to mitigate this vulnerability. If an immediate solution is required, follow the steps below using the Note Assistant:

  • Apply manual corrections as provided in the attachment.
  • Apply code correction instructions from the note using transaction SNOTE.
  • Ensure that Note 1497003 is applied as it is a prerequisite.

To enhance security and reduce dependencies among programs:

  • Create a directory structure that reflects the user name and/or program name.
  • Use this structure when setting up physical paths and file names for logical file paths and names.

Affected components

  • C-CEE 110_600
  • C-CEE 110_602
  • C-CEE 110_603
  • C-CEE 110_604

Full note on SAP: SAP Support Launchpad note 1961994

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More