SAP Security Note
High priority
SAP security note 1519060, "IS-H CH: Directory traversal in various reports", was released on 13.10.2011. Below are the symptom and the SAP recommended solution.
Description
Symptom
This note addresses a directory traversal vulnerability in various programs specific to the IS-H component for Switzerland (CH). The vulnerability allows a malicious user to read or write arbitrary files on the remote server, potentially leading to data corruption or altered system behavior.
Affected programs: RNWCHBI20, RNWCHBI30, RNWCHBI40, RNWCHBI50, RNWCHGALDAT, RNWCHLAB_LOAD, RNWCHNTPK00, RNWCHNTPK00K, RNWCHNTPKDRG00, RNWCHNTPKU0, RNWCHTARTYP_DOM, RNWCHTMQLDI, RNWCHTMSPART, RNWCHTM_ABGL, RNWCHTM_EINSP.
Solution
Implement SAP Note 1497003 first, as it is a prerequisite.
The reports listed above have logical file names identical to their report names. Using transaction FILE, call "Logical File Path Definition, Cross-Client", choose "New entries", and for each report enter: Logical file <REPORT NAME>, Name "Validation for <REPORT NAME>", Data format DIR, Application Area IS. Choose "Next Entry" (F8) and repeat for each report, then save.
Reason and prerequisites
The specified programs contain a vulnerability that allows a malicious user to read or write arbitrary files on the remote server, potentially leading to data corruption or altered system behavior.
References
Full note on SAP: SAP Support Launchpad note 1519060
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




