SAP security note 1511995, “CML/FIN-FSCM-CM: Potential Directory Traversal”, is a note. Below is the security information published by SAP for this note.
Description
SAP Security Note 1511995 addresses a critical directory traversal vulnerability found in the FS-CML (Migration of objects and collaterals) and FIN-FSCM-CM (Export/Import single records) modules. This vulnerability allows a malicious user to potentially write arbitrary files on the remote server, which can lead to data corruption or altered system behavior.
Impact
Exploiting this vulnerability can enable attackers to overwrite data on the remote system, compromising the integrity and reliability of the SAP environment. This can result in unauthorized changes, data loss, or further security breaches.
Solution
To mitigate this vulnerability, it is essential to implement the corrections outlined in SAP Note 1497003 – Potential directory traversals in applications. The steps provided in SAP Note 1497003 are prerequisites for the effective implementation of this security note.
Affected components
- FS-CML: Financial Services – Consumer and Mortgage Loans
- FIN-FSCM-CM: Financial Supply Chain Management – Cash Management
Additional information
This security note is part of a series addressing directory traversal vulnerabilities within SAP applications. Ensure all prerequisite notes are applied to maintain a secure SAP environment.
*Credits to Red Rays for support in providing this information.*
References
- 1497003 – Potential directory traversals in applications
- 1509869 – Market Data Interface: Potential Directory Traversal
Full note on SAP: SAP Support Launchpad note 1511995
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



