Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Directory traversal in /CEECV/ROFIRFUVDE07N, SAP security note 1953936

SAP Note 1953936
SAP Security Note
Medium priority

SAP security note 1953936, "Directory traversal in /CEECV/ROFIRFUVDE07N", is a program error note released on 18.02.2014. Below are the symptom, SAP recommended solution and the affected software components.

ComponentMiscellaneous > Country/Region-Specific Developments > Romania > use FI-LOC-FI-RO
CategoryProgram error
PriorityCorrection with medium priority
TypeSAP Security Note
Version1
StatusReleased for Customer
Released on18.02.2014
LanguageEnglish

Description

Symptom

/CEECV/ROFIRFUVDE07N contains a vulnerability through which an attacker can potentially write arbitrary files to the remote server, possibly corrupting data or altering system behavior.

Solution

As a general rule, SAP recommends that you install a solution by applying a Support Package. However, if you need to install a solution earlier, use the Note Assistant and follow the described instructions:

  • Apply manual corrections as given in the attachment.
  • Apply code correction instructions from the note using transaction SNOTE.
  • For additional information and instructions see Note 1497003. The corrections from Note 1497003 are a prerequisite for implementing this note.

The following logical file name has been created to enable the validation of physical file names: /CEECV/ROFI

Recommendations for setting up logical file names: To avoid maintaining a high number of logical file names, some of the programs share the same logical file name. Using the same logical file name for various programs creates dependencies among these programs. To securely separate data created by different users and different programs, try to create a directory structure that reflects the user name and/or program name and use this information when setting up the physical path and file names for the logical file paths and file names.

You can find more information about the Note Assistant in SAP Service Marketplace, under service.sap.com/note-assistant.

Reason and prerequisites

/CEECV/ROFIRFUVDE07N fails to correctly validate the path to which a user-submitted file is written. As a result, an attacker can potentially overwrite data in the remote system.

Affected components

  • C-CEE 110_600
  • C-CEE 110_602
  • C-CEE 110_603
  • C-CEE 110_604

Full note on SAP: SAP Support Launchpad note 1953936

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More