Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Directory Traversal vulnerability in SAP NetWeaver Log Viewer, SAP security note 2370876

SAP Note 2370876

SAP security note 2370876, "Directory Traversal vulnerability in SAP NetWeaver Log Viewer". Below are the symptom and SAP recommended solution.

Description

Symptom

SAP NetWeaver Log Viewer allows an attacker to exploit insufficient validation of path information provided by users, thus characters representing ‘traverse to parent directory’ are passed through to the file APIs.

Impacts of Directory Traversal vulnerability:

  • Read Arbitrary Files: Attacker could read content of arbitrary files on the remote server and expose sensitive data.
  • Modify Files: Attacker could overwrite, delete, or corrupt arbitrary files on the remote server.

Solution

Implement the Support Packages and Patches referenced by this SAP Note.

CVSS

Score 5.9 Vector: AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:H

References

Full note on SAP: SAP Support Launchpad note 2370876

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More