SAP Security Note
Medium priority
SAP security note 1264767, "The subfolder parameter does not allow ".." anymore", is a program error note released on 08.10.2009. Below are the symptom and SAP recommended solution.
Description
Symptom
Attackers may gain access while browsing to restricted parts in the Web server directory.
Solution
This issue has been corrected in BPC 5.1 SP4. The subfolder parameter in the file manager service has been updated to disallow the use of “..”, preventing directory traversal attacks.
Reason and prerequisites
Attackers can access restricted parts of the Web server directory by manipulating URLs directly instead of following legitimate links. This type of attack is known as “forceful browsing.”
Example: http://localhost/OSoft/Common/ShowFile.aspx?FILE=../../../../OSoftInstall.log&TYPE=DOC
References
This note refers to
Full note on SAP: SAP Support Launchpad note 1264767
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



