Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Potential Directory Traversal in XX-CSC-IL, SAP security note 1531054

SAP Note 1531054

SAP security note 1531054, "Potential Directory Traversal in XX-CSC-IL". Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

Potential Directory Traversal in the following components: XX-CSC-IL.

Solution

Please refer to SAP Note 1497003 – Potential directory traversals in applications for additional information and instructions. The corrections from note 1497003 are a prerequisite for implementation of this note.

Logical file names used in this solution to enable the validation of physical file names: /ATL/BEZEQ_FILE, /ATL/BEZEQ_ZAHAV_FILE, /ATL/BEZEQ_HEADER, /ATL/BEZEQ_LINE (Report /ATL/DBZK01REP).

Reason and prerequisites

The programs contained in the correction instructions contain vulnerabilities through which a malicious user can potentially read arbitrary files on the remote server, possibly disclosing confidential information. Some of the programs contained in the correction instructions contain a vulnerability through which a malicious user can potentially write arbitrary files on the remote server, possibly corrupting data or altering system behavior.

CVSS

Score 0

References

Affected components

  • C-CEE: From 110_604 to 110_604

Full note on SAP: SAP Support Launchpad note 1531054

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More