Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

RE-FX-SC, RE-FX-MM Potential Directory Traversal, SAP security note 1509631

SAP Note 1509631High priority

SAP security note 1509631, "RE-FX-SC, RE-FX-MM: Potential Directory Traversal", is a program error note released on December 14, 2010. Below are the symptom, SAP recommended solution and the affected software components.

CategoryProgram error
PriorityCorrection with high priority
Version4
StatusReleased for Customer
Released onDecember 14, 2010

Description

Symptom

Potential Directory Traversal in the following components: RE-FX-SC, RE-FX-MM.

Solution

Please refer to Note 1497003 for additional information and instructions. The corrections from Note 1497003 are a prerequisite for implementing this note.

Reason and prerequisites

A vulnerability exists that allows a malicious user to write arbitrary files on the remote server, potentially corrupting data or altering system behavior.

References

Affected components

  • Real Estate Management > Flexible Real Estate Management > Service Charge Settlement (RE-FX-SC)
  • RE-FX-MM: Mandate Management
  • EA-APPL 110
  • EA-APPL 200
  • EA-APPL 500
  • EA-APPL 600
  • EA-APPL 602
  • EA-APPL 603
  • EA-APPL 604
  • EA-APPL 605

Full note on SAP: SAP Support Launchpad note 1509631

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More