SAP Security Note
Medium priority
SAP security note 1961948, "Directory traversal in /CCEE/FISIRFEBKA00", is a program error note released on 18.02.2014. Below are the symptom, reason and prerequisites, SAP recommended solution and the affected software components.
Description
Symptom
/CCEE/FISIRFEBKA00 contains a vulnerability through which an attacker can potentially read arbitrary files on the remote server, possibly disclosing confidential information.
Solution
As a general rule, SAP recommends that you install a solution by applying a Support Package. However, if you need to install a solution earlier, use the Note Assistant and follow the described instructions:
- Apply manual corrections as given in the attachment.
- Apply code correction instructions from the note using transaction SNOTE.
- For additional information and instructions see Note 1497003. The corrections from Note 1497003 are a prerequisite for implementing this note.
The following logical file name has been created to enable the validation of physical file names: /CCEE/SIFI
To avoid maintaining a high number of logical file names, some of the programs share the same logical file name. Using the same logical file name for various programs creates dependencies among these programs. To securely separate data created by different users and different programs, try to create a directory structure that reflects the user name and/or program name and use this information when setting up the physical path and file names for the logical file paths and file names.
More information about the Note Assistant is available in SAP Service Marketplace, under service.sap.com/note-assistant.
Reason and prerequisites
/CCEE/FISIRFEBKA00 fails to correctly validate the path that is used to reference a file that is read from the remote server. As a result, an attacker can potentially direct the program to an arbitrary other file in the system, disclosing its contents.
Affected components
- C-CEE from 110_600 to 110_600
- C-CEE from 110_602 to 110_602
- C-CEE from 110_603 to 110_603
- C-CEE from 110_604 to 110_604
Full note on SAP: SAP Support Launchpad note 1961948
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




