Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Potential Directory Traversal in PY-NL, SAP security note 1598791

SAP Note 1598791

SAP security note 1598791, “Potential Directory Traversal in PY-NL”, is a note. Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

Potential Directory Traversal in Component PY-NL.

Solution

  • Apply the relevant Support Package for your release. Refer to SAP Note 1497003 for additional information and instructions. Corrections from this note are a prerequisite for implementing this security note.
  • Follow the detailed manual steps provided in the Correction Instructions section of the note to maintain the physical paths. This includes creating and configuring the logical file name HR_NL_CRTS_OUT used by program RPUTSVN0.

Reason and prerequisites

The programs contained in the correction instructions have vulnerabilities that allow a malicious user to potentially read arbitrary files on the remote server, possibly disclosing confidential information. Some of the programs contain vulnerabilities that allow a malicious user to potentially write arbitrary files on the remote server, possibly corrupting data or altering system behavior.

References

Affected components

  • SAP_HR 46C
  • SAP_HRCNL (470, 500, 600, 604)

Full note on SAP: SAP Support Launchpad note 1598791

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More