SAP security note 1953942, "Directory traversal in /CEECV/ROFI_VIES_394". Below are the symptom, reason and prerequisites, SAP recommended solution and the affected software components.
Description
Symptom
/CEECV/ROFI_VIES_394 contains a vulnerability that allows an attacker to potentially write arbitrary files to the remote server, possibly corrupting data or altering system behavior.
Solution
SAP generally recommends applying a Support Package to install a solution. However, if you need to implement the solution sooner, you can use the Note Assistant and follow these instructions:
- Apply manual corrections as provided in the attachment.
- Apply code correction instructions from the note using transaction SNOTE.
- For additional information and instructions, refer to Note 1497003. The corrections from Note 1497003 are a prerequisite for implementing this note.
To avoid maintaining a high number of logical file names, some programs share the same logical file name, which creates dependencies among these programs. To securely separate data created by different users and programs, create a directory structure that reflects the user name and/or program name and use this information when setting up the physical path and file names for the logical file paths and file names.
Reason and prerequisites
/CEECV/ROFI_VIES_394 fails to correctly validate the path to which a user-submitted file is written. As a result, an attacker can potentially overwrite data in the remote system.
Affected components
- C-CEE 110_600 to 110_600
- C-CEE 110_602 to 110_602
- C-CEE 110_603 to 110_603
- C-CEE 110_604 to 110_604
Full note on SAP: SAP Support Launchpad note 1953942
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




