SAP security note 1507936, "HCM: Potential Directory Traversal in German Payroll PY-DE". Below are the SAP recommended solution and the affected software components.
Description
Solution
To mitigate this vulnerability, implement the corresponding support package or apply the correction instructions provided in this note.
References
- Note 1591557 – Potential directory traversal in utility report RPUOTFL0
- Note 1507935 – HCM: Potential Directory Traversal Internat. Payroll PY-XX
- Note 1506219 – Checkman correction
- Note 1498228 – ZfA/RBM: New methods for application server
- Note 1497003 – Potential directory traversals in applications
Affected components
- SAP_HR: 31I, 40B, 45B, 46B, 46C
- SAP_HRCDE: 470, 500, 600, 604
Full note on SAP: SAP Support Launchpad note 1507936
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
