Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Directory traversal in /CEECV/RO_ANN_FS_EXPORT, SAP security note 1953974

SAP Note 1953974

SAP security note 1953974, "Directory traversal in /CEECV/RO_ANN_FS_EXPORT", is a note. Below are the symptom and SAP recommended solution.

Description

Symptom

/CEECV/RO_ANN_FS_EXPORT contains a vulnerability through which an attacker can potentially write arbitrary files to the remote server, possibly corrupting data or altering system behavior.

Solution

SAP recommends installing a solution by applying a Support Package. If an earlier installation is required, use the Note Assistant and follow the instructions below:

  • Manual Corrections: Apply manual corrections as provided in the attachment Guide – Logical File Path, Name (ROFI).docx.
  • Code Correction: Use transaction SNOTE to apply code correction instructions from the note. Ensure that you have applied Note 1497003, as it is a prerequisite for implementing this note.
  • Logical File Name Setup: A logical file name /CEECV/ROFI has been created to enable the validation of physical file names. Create a directory structure that reflects the user name and/or program name to securely separate data created by different users and programs, and use this information when setting up the physical path and file names for the logical file paths and file names.

For more information about the Note Assistant, visit SAP Service Marketplace.

Reason and prerequisites

/CEECV/RO_ANN_FS_EXPORT fails to correctly validate the path to which a user-submitted file is written. As a result, an attacker can potentially overwrite data in the remote system.

Full note on SAP: SAP Support Launchpad note 1953974

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More