SAP security note 1794951, "Directory traversal in XX-CSC-BR", is a note. Below are the symptom and SAP recommended solution.
Description
Symptom
Potential Directory Traversal in:
- XX-CSC-BR
Read-write or write directory traversal: The report contained in the correction instructions includes a vulnerability that allows an attacker to potentially write arbitrary files to the remote server, which could corrupt data or alter system behavior.
Solution
Please refer to Note 1497003 for additional information and instructions. The corrections from this note are a prerequisite for implementing Note 1794951.
Reason and prerequisites
The report in the correction instructions fails to properly validate the path where a user-submitted file is written. As a result, an attacker can potentially overwrite data on the remote system.
Prerequisites: You have implemented Note 1782959.
References
- Note 1782959 – Directory traversal in XX-CSC-BR
- Note 1497003 – Potential directory traversals in applications
Full note on SAP: SAP Support Launchpad note 1794951
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



