SAP Security Note
High priority
SAP security note 1534637, "RN1_CORRECT_CORDTYPES: Potential Directory Traversal", is a program error note released on December 14, 2010. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
A potential Directory Traversal vulnerability exists in the RN1_CORRECT_CORDTYPES component. This vulnerability allows a malicious user to write arbitrary files on the remote service, potentially corrupting data or altering system behavior.
Solution
Apply the source code corrections provided in the support package patches.
References
- SAP Note 1624291: Syntax error when implementing a security note
- SAP Note 1510866: RN1_CORRECT_CORDTYPES: Potential Directory Traversal
- SAP Note 1497003: Potential directory traversals in applications
Affected components
- IS-H: 472, 600, 602, 603, 604, 605
Full note on SAP: SAP Support Launchpad note 1534637
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




