Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Directory Traversal in CL_FP_ADS_HTTP_EXTENSION, SAP security note 1450228

SAP Note 1450228High priority

SAP security note 1450228, "Directory Traversal in CL_FP_ADS_HTTP_EXTENSION", is a program error note released on June 8, 2010. Below are the symptom, SAP recommended solution and affected software components.

CategoryProgram error
StatusReleased for Customer
Released onJune 8, 2010

Description

Symptom

SAP Security Note 1450228 addresses a directory traversal vulnerability in the ABAP ICF handler CL_FP_ADS_HTTP_EXTENSION. This vulnerability allows a malicious user to write arbitrary files on the ABAP server, potentially leading to data corruption. Unauthorized file writes: attackers can write arbitrary files to the ABAP server. Data corruption: potential for corrupting critical data on the server.

Solution

Apply the relevant support packages provided in this security note to mitigate the vulnerability. The correction includes verifications of file paths and file name patterns to prevent directory traversal attacks.

Affected components

  • SAP_BASIS 700 to 702
  • SAP_BASIS 710 to 720

Full note on SAP: SAP Support Launchpad note 1450228

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More