Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Directory Traversal in Payroll Belgium PY-BE, SAP security note 1598285

SAP Note 1598285
SAP Security Note
High priority

SAP security note 1598285, "Directory Traversal in Payroll Belgium PY-BE", is a note released on August 9, 2011. Below are the symptom, SAP recommended solution and the affected software components.

ComponentPayroll > Belgium (PY-BE)
PriorityCorrection with high priority
TypeSAP Security Note
StatusReleased for Customer
Released onAugust 9, 2011
LanguageEnglish

Description

Symptom

The Payroll Belgium (PY-BE) module contains a vulnerability that allows a malicious user to perform directory traversal, potentially writing arbitrary files on the remote server. This can lead to data corruption or alteration of system behavior. Additionally, improperly maintained filenames can cause short dumps in specific cases.

Solution

Please refer to SAP Note 1497003 for additional information.

Create Logical File Path HR_BE_FILE_PATH_DOWN: navigate to the IMG activity "Cross-Client Maintenance of File Names and Paths" (SAP NetWeaver -> Application Server -> System administration -> Platform-Independent File Names) or use transaction FILE. Insert a new entry HR_BE_FILE_PATH_DOWN in the "Logical File Path Definition" node and save it. Double-click "Assignment of Physical Paths to Logical Path" for the new entry and maintain entries according to your operating system and the desired physical path.

Create Logical File Name HR_BE_DOWNLOAD_FILE_PD: navigate to the same IMG activity or use transaction FILE. Insert a new entry HR_BE_DOWNLOAD_FILE_PD in the "Logical File Name Definition, Cross-Client" node and maintain the following values:

  • Logical File: HR_BE_DOWNLOAD_FILE_PD
  • Name: File created via Pensioners Declaration (download)
  • Data Format: DIR
  • Applicat. Area: HR
  • Logical Path: HR_BE_FILE_PATH_DOWN

Reason and prerequisites

In Payroll Belgium, the system fails to correctly validate the path where a user-submitted file is written. This oversight enables a malicious user to overwrite data on the remote system.

References

Affected components

  • SAP_HR: 46B, 46C
  • SAP_HRCBE: 470, 500, 600, 604

Full note on SAP: SAP Support Launchpad note 1598285

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More