SAP security note 1517930, "Travel Expenses: Potential directory traversal", is a program error note released on 14.12.2010. Below are the symptom, SAP recommended solution, reason and prerequisites and references.
Description
Symptom
Potential Directory Traversal in the following components: FI-TV.
Solution
Please read SAP Note 1497003 for this topic. The corrections in this note are required for this one.
With this note, the following logical filenames will be created to check the physical file names:
- FI_TV_RPRAPA00 – used by programs RPRAPA00, RPRAPAFO and RPRAPAFO_ALV
- FI_TV_AIRPLUS – used by program RPR_AIRP_LRS_TO_FI_FORMS
- FI_TV_AMEX_BTA – used by program RPR_AMEX_BTA_TO_FI_FORMS
Reason and prerequisites
There is a potential directory traversal vulnerability.
References
This note refers to
Full note on SAP: SAP Support Launchpad note 1517930
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




