SAP Security Note
Medium priority
SAP security note 1961952, "Directory traversal in /CCEE/SIFI_EXPORT_GL_LINE", is a program error note released on 18.02.2014. Below are the symptom, reason and prerequisites, SAP recommended solution, CVSS score and the affected software components.
Description
Symptom
/CCEE/SIFI_EXPORT_GL_LINE contains a vulnerability through which an attacker can potentially write arbitrary files to the remote server, possibly corrupting data or altering system behavior.
Solution
As a general rule, SAP recommends that you install a solution by applying a Support Package. However, if you need to install a solution earlier, use the Note Assistant to implement the correction instruction. More information about the Note Assistant is available in SAP Service Marketplace, under service.sap.com/note-assistant.
Reason and prerequisites
/CCEE/SIFI_EXPORT_GL_LINE fails to correctly validate the path to which a user-submitted file is written. As a result, an attacker can potentially overwrite data in the remote system.
CVSS
Score 0
Affected components
- C-CEE 110_600 to 110_600
- C-CEE 110_602 to 110_602
- C-CEE 110_603 to 110_603
- C-CEE 110_604 to 110_604
Full note on SAP: SAP Support Launchpad note 1961952
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



