SAP security note 1599094, “HCM: Directory traversal in PT-TL.” Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
PT-TL contains a vulnerability through which a malicious user can potentially read arbitrary files on the remote server, possibly disclosing confidential information.
PT-TL contains a vulnerability through which a malicious user can potentially write arbitrary files on the remote server, possibly corrupting data or altering system behavior.
Solution
For additional information and instructions, see Note 1497003. The corrections from Note 1497003 are a prerequisite for implementing this note.
The following logical file names have been created to enable the validation of physical file names:
- HR_XX_DIR_RPTEDO00: RPTEDO00
- HR_XX_DIR_RPTEUP00: RPTEUP00
- HR_XX_DIR_RPTEUP10: RPTEUP10
- HR_XX_DIR_RPTEZL00: RPTEZL00
- HR_XX_DIR_RPTX2010: RPTX2010
- HR_XX_DIR_RPWI0000: RPWI0000
Reason and prerequisites
PT-TL fails to correctly validate the path that is used to reference a file that is read from the remote server. As a result, a malicious user can potentially direct the program to an arbitrary other file in the system, disclosing its contents.
PT-TL fails to correctly validate the path to which a user-submitted file is written. As a result, a malicious user can potentially overwrite data in the remote system.
CVSS
Score 0
References
This note refers to
Affected components
- SAP_HR 30F to 30F
- SAP_HR 31H to 31I
- SAP_HR 40B to 40B
- SAP_HR 45B to 45B
- SAP_HR 46B to 46B
- SAP_HR 46C to 46C
- SAP_HRRXX 470 to 470
- SAP_HRRXX 500 to 500
- SAP_HRRXX 600 to 600
- SAP_HRRXX 604 to 604
Full note on SAP: SAP Support Launchpad note 1599094
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




