SAP security note 1509235, "Directory Traversal in RFC modules in classification". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
The RFC modules in classification (function group CLBA) have a vulnerability that permits directory traversal, enabling unauthorized file writes on the remote server.
Solution
Implement the changes as outlined in the advance correction. Additionally, refer to Note 1497003 for prerequisite program changes required by this note.
Reason and prerequisites
Function modules CLBA_CLASSIF_FILE_REMOTE_HOST and CLBA_UPDATE_FILE_REMOTE_HOST do not properly validate the path for user-submitted files. This oversight allows attackers to overwrite data on the remote system.
Prerequisites: SAP_ABA component versions 702 and 730. Installed before applying this note:
- SAP Note 1441392 – Error handling RCCLBI03 and CLAP_DDB_DELETE_CLASSIFICATION
- SAP Note 1453844 – RCCLBI03: Too much memory consumption
- SAP Note 1499042 – Directory Traversal in batch input reports in class system
- SAP Note 1497003 – Potential directory traversals in applications
References
- SAP Note 1514017 – Directory Traversal in transactions CL6E and CL6F
- SAP Note 1510773 – Directory Traversal in RFC modules in classification
- SAP Note 1509794 – Directory Traversal in transactions CL6E and CL6F
- SAP Note 1499042 – Directory Traversal in batch input reports in class system
- SAP Note 1497003 – Potential directory traversals in applications
Affected components
- SAP_ABA 702
- SAP_ABA 730
Full note on SAP: SAP Support Launchpad note 1509235
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



