Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

HCMPotential Directory Traversal in Payroll Singapore PY-SG, SAP security note 1517828

SAP Note 1517828SAP Security NoteHigh priority

SAP security note 1517828, "HCM: Potential Directory Traversal in Payroll Singapore PY-SG", is a program error note released on December 14, 2010. Below are the symptom, SAP recommended solution, reason and prerequisites, CVSS score, references and affected software components.

ComponentPayroll > Singapore (PY-SG)
CategoryProgram error
PriorityCorrection with high priority
TypeSAP Security Note
Version1
StatusReleased for Customer
Released onDecember 14, 2010

Description

Symptom

Potential Directory Traversal in PY-SG.

Solution

Refer to Note 1497003 for additional information and instructions. Ensure that corrections from the following notes are implemented before applying this security note:

Reason and prerequisites

Programs in the correction instructions of Note 1515775 contain vulnerabilities that allow malicious users to read arbitrary files on the remote server, potentially disclosing confidential information. Some programs in the correction instructions of Note 1515775 also have vulnerabilities that enable malicious users to write arbitrary files on the remote server, potentially corrupting data or altering system behavior.

CVSS

Score 0

References

Affected components

  • SAP_HR (46B, 46C)
  • SAP_HRCSG (470, 500, 600, 604)

Full note on SAP: SAP Support Launchpad note 1517828

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More