Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Directory traversal in PY-FR-IE, SAP security note 1620072

SAP Note 1620072

SAP security note 1620072, “Directory traversal in PY-FR-IE”. Below are the symptom and SAP recommended solution.

Description

Symptom

The directory traversal vulnerability in PY-FR-IE allows a malicious user to potentially write arbitrary files on the remote server. This can lead to data corruption or alteration of system behavior.

Solution

Refer to SAP Note 1497003 for additional information and detailed instructions. Implementing the corrections from SAP Note 1497003 is a prerequisite for applying SAP Note 1620072.

Steps to implement:

  • Support Packages: apply the relevant HR Support Packages as listed below, or implement the correction instructions provided in SAP Note 1497003.
  • Define Aliases: after implementing the note, define aliases for the logical file name HR_FR_P06I_IN in view V_FILEALIA. Use the provided parameters (<PARAM_1> for program name and <PARAM_2> for file type – TEDC or TEDI) when building the physical file name.

Reason and prerequisites

The program described in the correction instructions contains a vulnerability that can be exploited to write arbitrary files on the remote server. This could result in data corruption or changes to system behavior.

References

Full note on SAP: SAP Support Launchpad note 1620072

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More