SAP Security Note
High priority
SAP security note 1533478, "FI – Potential Directory Traversal", is a program error note released on 14.12.2010. Below are the symptom and the SAP recommended solution.
Description
Symptom
Potential Directory Traversal for RFIDUS99.
Solution
Please refer to note 1497003 for additional information and instructions. The corrections from note 1497003 are a prerequisite for the implementation of this note.
Logical file name used in this solution: FI_RFIDUS99C_FILE, used by program RFIDUS99C. Logical file path used in this solution: FI_IDFIUS_FILE_PATH.
Reason and prerequisites
- The programs contained in the correction instructions contain vulnerabilities through which a malicious user can potentially read arbitrary files on the remote server, possibly disclosing confidential information.
- Some of the programs contained in the correction instructions contain a vulnerability through which a malicious user can potentially write arbitrary files on the remote server, possibly corrupting data or altering system behavior.
References
This note refers to
Full note on SAP: SAP Support Launchpad note 1533478
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



