SAP Security Note
High Priority
SAP security note 1900200, "Directory Traversal Vulnerability in BC-SRV-ARL", is a program error note released on December 10, 2013. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
The vulnerability exists in Archivelink, where it fails to correctly validate the path to which a user-submitted file is written. Consequently, an attacker can overwrite data in the remote system.
Solution
Refer to Note 1497003 for additional information and instructions. The corrections from this note are prerequisites for implementing Note 1900200.
Manual pre-implementation steps:
- Create Logical File Definitions: go to the FILE transaction, create a Logical Filepath definition with the logical filepath ARCHIVLINK_SERVERPATH_LP and save. Create a Logical Filename Definition with Logical File ARCHIVLINK_SERVERPATH, Data Format DIR, Logical Path ARCHIVLINK_SERVERPATH_LP, and save the entry.
- Add Exception to Function Modules: go to transaction SE37, open the function module ARCHIVFILE_CLIENT_TO_SERVER, enter Edit mode, navigate to the Exceptions tab, and add the exception NO_AUTHORIZATION if it does not exist. Save and activate the function module, then repeat the same steps for the function module ARCHIVFILE_SERVER_TO_CLIENT.
CVSS
Score 4.6 Vector: AV:N/AC:H/AU:S/C:P/I:P/A:P
Affected components
- SAP_APPL: Releases 31I, 40B, 45B
- SAP_BASIS: Releases 46B to 46D, 620 to 640, 700 to 702, 710 to 730, 731, 740
Full note on SAP: SAP Support Launchpad note 1900200
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




