SAP Security Note
High priority
SAP security note 1571280, "SLL-LEG-FUN-UPL: Directory Traversal", is a program error note released on September 13, 2011. Below are the symptom and SAP recommended solution.
Description
Symptom
Potential Directory Traversal in the following component: SLL-LEG-FUN-UPL.
Solution
To mitigate these vulnerabilities, please refer to SAP Note 1497003 for additional information and instructions. Implementing the corrections from both Note 1497003 and Note 1556515 is a prerequisite for applying this security note.
The following logical file name and path have been created to validate physical file names and paths: Logical File Name: SLL_LEG_FUN_UPL; Logical File Path: SLL_LEG_FUN_UPL; Program Using This Logical File Name: /SAPSLL/MARC_UPLOAD_R3; Parameters Used: <PARAM_1> Program name.
Reason and prerequisites
Read Vulnerability. The program included in the correction instruction contains vulnerabilities that allow a malicious user to read arbitrary files on the remote server, potentially disclosing confidential information.
Write Vulnerability. Some programs in the correction instructions enable a malicious user to write arbitrary files on the remote server, possibly leading to data corruption or altered system behavior.
References
- 1556515 – SLL-LEG-FUN-UPL: Directory Traversal
- 1497003 – Potential directory traversals in applications
Full note on SAP: SAP Support Launchpad note 1571280
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
