Medium priority
SAP security note 1511114, “ICM: Potential Directory Traversal”, is a program error note released on December 14, 2010. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
SAP Security Note 1511114 addresses a potential directory traversal vulnerability in the Incentive and Commission Management – Technical Integration, Tools (ICM-TO) component. This vulnerability allows malicious users to read arbitrary files on the server, potentially disclosing confidential information, or to write arbitrary files, which could corrupt data or alter system behavior.
Solution
- Refer to SAP Note 1497003 for additional information and instructions. The corrections from this note are required before implementing SAP Note 1511114.
- Follow the instructions provided in the “Manual Activities” section of the note to create the necessary logical file paths and file names. This includes creating logical paths and names using transaction FILE as specified in the correction instructions.
- After implementing the changes, re-generate the ICM application to ensure that the updates are reflected.
Affected components
- EA-APPL (110, 200, 500, 600, 602, 603, 604, 605)
Full note on SAP: SAP Support Launchpad note 1511114
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




