SAP security note 2370876, "Directory Traversal vulnerability in SAP NetWeaver Log Viewer". Below are the symptom and SAP recommended solution.
Description
Symptom
SAP NetWeaver Log Viewer allows an attacker to exploit insufficient validation of path information provided by users, thus characters representing ‘traverse to parent directory’ are passed through to the file APIs.
Impacts of Directory Traversal vulnerability:
- Read Arbitrary Files: Attacker could read content of arbitrary files on the remote server and expose sensitive data.
- Modify Files: Attacker could overwrite, delete, or corrupt arbitrary files on the remote server.
Solution
Implement the Support Packages and Patches referenced by this SAP Note.
CVSS
Score 5.9 Vector: AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:H
References
Full note on SAP: SAP Support Launchpad note 2370876
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
