SAP security note 1556515, "SLL-LEG-FUN-UPL: Directory Traversal". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Potential directory traversal in the following component: SLL-LEG-FUN-UPL.
Solution
- Prerequisite: Apply Security Note 1497003 which addresses additional vulnerabilities and is required before implementing this note.
- Implement the corrections provided in this note to mitigate the directory traversal vulnerabilities.
Reason and prerequisites
The programs in the correction instructions contain vulnerabilities that allow malicious users to read arbitrary files on the remote server.
Some programs allow malicious users to write arbitrary files on the remote server, potentially corrupting data or altering system behavior.
CVSS
Score 0
References
- SAP Note 1571280 – SLL-LEG-FUN-UPL: Directory Traversal
- SAP Note 1497003 – Potential directory traversals in applications
Affected components
- SLL-LEG 710
- SLL-LEG 720
- SLL-LEG 800
- SLL-LEG 900
Full note on SAP: SAP Support Launchpad note 1556515
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



