SAP Security Note
High priority
SAP security note 1555924, "Update #1 for Security Note 1512352", is a program error note released on 13.09.2011. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Correction instructions for the directory traversal vulnerability described in Security Note 1512352 must be corrected for all releases. The corrected correction instructions have been added to this note.
Even though you have maintained Customizing for the logical file names for the input file and output file of the report RCCLBI03, the physical file names that are assigned are not identified as valid.
Solution
Implement the correction instructions.
If you have not yet implemented Note 1512352, it is implemented automatically as a required note.
If you want to store the output file on the application server, use the logical file name CLASSIFICATION_ERROR. The name defines the path under which the output file is saved. The system suggests RCCLBI03.ERROR as the file name, but you can choose your own file name. The path is not specified either on the presentation server. Here, CLASSIFICATION_ERROR (if defined) represents a default value.
CLASSIFICATION_ERROR must also be defined in Customizing.
Reason and prerequisites
Security Note 1512352 contains correction instructions that are incorrect and require a correction.
References
Affected components
- SAP_APPL: 31I, 40B, 45B, 46B, 46C
- SAP_ABA: 620, 640, 700 to 702, 710 to 711, 730
Full note on SAP: SAP Support Launchpad note 1555924
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
