High priority
SAP security note 1598698, "Potential Directory Traversal in PA-PF-NL", is a note released on October 11, 2011. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
A potential Directory Traversal vulnerability has been identified in the PA-PF-NL component. This vulnerability allows a malicious user to read arbitrary files on the remote server, which may lead to the disclosure of confidential information. Additionally, there is a risk of unauthorized writing and deletion of files, potentially corrupting data or altering system behavior.
Solution
- Ensure that SAP Note 1497003 is implemented prior to applying this security note.
- Follow the detailed manual instructions provided within the security note to configure logical file paths and ensure secure separation of data. This includes creating logical file names and mapping them to physical file paths to prevent unauthorized access.
References
Affected components
- SAP_HR (46C)
- SAP_HRCNL (470, 500, 600, 604)
Full note on SAP: SAP Support Launchpad note 1598698
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
