Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Directory traversal in Program /BGLOCS/VATREPORT07, SAP security note 1964200

SAP Note 1964200
SAP Security Note
Medium priority

SAP security note 1964200, "Directory traversal in Program /BGLOCS/VATREPORT07", is a note released on 18.02.2014. Below are the symptom and SAP recommended solution.

ComponentMiscellaneous > Country/Region-Specific Developments > Bulgaria > use FI-LOC-FI-BG
PriorityCorrection with medium priority
TypeSAP Security Note
StatusReleased for Customer
Released on18.02.2014
LanguageEnglish

Description

Symptom

Program /BGLOCS/VATREPORT07 contains a directory traversal vulnerability that allows an attacker to potentially write arbitrary files to the remote server. This can lead to data corruption or alteration of system behavior.

An attacker exploiting this vulnerability can overwrite data on the remote system, posing significant security risks.

Solution

  1. Apply Manual Corrections: Download and apply the manual corrections provided in the attachment Guide – Logical File Path, Name_1964200.docx.
  2. Apply Code Corrections via SNOTE: Use transaction SNOTE to apply the code correction instructions from this note.

Full note on SAP: SAP Support Launchpad note 1964200

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More