SAP security note 1450228, "Directory Traversal in CL_FP_ADS_HTTP_EXTENSION", is a program error note released on June 8, 2010. Below are the symptom, SAP recommended solution and affected software components.
Description
Symptom
SAP Security Note 1450228 addresses a directory traversal vulnerability in the ABAP ICF handler CL_FP_ADS_HTTP_EXTENSION. This vulnerability allows a malicious user to write arbitrary files on the ABAP server, potentially leading to data corruption. Unauthorized file writes: attackers can write arbitrary files to the ABAP server. Data corruption: potential for corrupting critical data on the server.
Solution
Apply the relevant support packages provided in this security note to mitigate the vulnerability. The correction includes verifications of file paths and file name patterns to prevent directory traversal attacks.
Affected components
- SAP_BASIS 700 to 702
- SAP_BASIS 710 to 720
Full note on SAP: SAP Support Launchpad note 1450228
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



