SAP Security Note
High priority
SAP security note 1602328, “Directory traversal in PY-FR”, is released on November 8, 2011. Below are the symptom and SAP recommended solution.
Description
Symptom
This security note addresses a directory traversal vulnerability in the PY-FR component of SAP Payroll. A malicious user can exploit this vulnerability to write arbitrary files on the remote server, potentially leading to data corruption or altered system behavior.
Exploiting this vulnerability allows unauthorized file creation on the server, which can compromise data integrity and system functionality.
Solution
To mitigate this vulnerability:
- Use the ‘Path and file name’ Field: When executing the program in the background, use the ‘Path and file name’ field on the selection screen to store the output list in a file on the application server. When executing the program in the foreground, utilize the ‘Download’ feature in the ALV display to save the list to a file.
- Implement Prerequisite Corrections: Refer to SAP Note 1497003 for additional information and instructions. Ensure that the corrections from SAP Note 1497003 are implemented as they are prerequisites for this note.
- Support Packages: Apply the relevant support packages as listed in the “Support Package” section below.
References
Full note on SAP: SAP Support Launchpad note 1602328
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
