High priority
SAP security note 1514017, "Directory Traversal in transactions CL6E and CL6F", is a note released on 14.12.2010. Below are the symptom and SAP recommended solution.
Description
Symptom
Transactions CL6E and CL6F fail to correctly validate the path with which a file that is read from the remote server is referenced. This means that an attacker can potentially point the program to an arbitrary other file on the system, disclosing its contents.
Solution
The corrections attached to this note enhance the corrections contained in Note 1509794. Implement the changes in accordance with this advance correction.
- Transaction CL6E uses the logical file name DIN_CLASS.
- Transaction CL6F uses the logical file name DIN_CHARACTERISTIC.
Also refer to the information contained in Note 1497003. The program changes from Note 1497003 are also a prerequisite for this note.
References
- 1510773 – Directory Traversal in RFC modules in classification
- 1509794 – Directory Traversal in transactions CL6E and CL6F
- 1509235 – Directory Traversal in RFC modules in classification
- 1497003 – Potential directory traversals in applications
Full note on SAP: SAP Support Launchpad note 1514017
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
