SAP Security Note
High priority
SAP security note 1488541, "Potential Directory Traversal in RCCULC01", is a program error note released on 14.12.2010. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Potential directory traversal in obsolete report RCCULC01.
Solution
The affected program is obsolete and the erroneous code has been removed.
Reason and prerequisites
The program RCCULC01 contains a vulnerability through which a malicious user can potentially write arbitrary files on the remote server, possibly corrupting data or altering system behavior.
References
Affected components
- SAP_APPL versions 46C, 470, 500, 600, 602, 603, 604, 605
Full note on SAP: SAP Support Launchpad note 1488541
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
