SAP security note 1531054, "Potential Directory Traversal in XX-CSC-IL". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Potential Directory Traversal in the following components: XX-CSC-IL.
Solution
Please refer to SAP Note 1497003 – Potential directory traversals in applications for additional information and instructions. The corrections from note 1497003 are a prerequisite for implementation of this note.
Logical file names used in this solution to enable the validation of physical file names: /ATL/BEZEQ_FILE, /ATL/BEZEQ_ZAHAV_FILE, /ATL/BEZEQ_HEADER, /ATL/BEZEQ_LINE (Report /ATL/DBZK01REP).
Reason and prerequisites
The programs contained in the correction instructions contain vulnerabilities through which a malicious user can potentially read arbitrary files on the remote server, possibly disclosing confidential information. Some of the programs contained in the correction instructions contain a vulnerability through which a malicious user can potentially write arbitrary files on the remote server, possibly corrupting data or altering system behavior.
CVSS
Score 0
References
Affected components
- C-CEE: From 110_604 to 110_604
Full note on SAP: SAP Support Launchpad note 1531054
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



