SAP Security Note
High priority
SAP security note 1586451, "Directory traversal in alert log trace", is a program error note released on 13.12.2011. Below are the symptom and SAP recommended solution.
Description
Symptom
The function module C_ORA_READ_TRACEFILE_RE contains a vulnerability through which a malicious user can potentially read arbitrary files on the remote server, possibly disclosing confidential information.
Solution
Implement the corrections.
Reason and prerequisites
The function module C_ORA_READ_TRACEFILE_RE fails to correctly validate the path that is used to reference a file that is read from the remote server. As a result, a malicious user can potentially direct the program to an arbitrary other file in the system, disclosing its contents.
Full note on SAP: SAP Support Launchpad note 1586451
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




