SAP security note 1620133, "Directory Traversal in PY-AU-CE", is a note. Below are the symptom and SAP recommended solution.
Description
Symptom
PY-AU-CE: Potential Directory Traversal in RPCPBSQ0_CE
Solution
Please refer to Note 1497003 for additional information and instructions. The corrections from Note 1497003 are a prerequisite for implementing this note.
Logical File Name Used in this Solution: the following logical file names have been created to enable the validation of physical file names:
- Logical filename: HR_AU_DIR_ATO_FILE_NAME
- Program Using this logical filename: RPCPBSQ0_CE
- Logical File Path Used in this Solution: HR_AU_FILENAME
Reason and prerequisites
1. The programs contained in the correction instructions have vulnerabilities that allow a malicious user to potentially read arbitrary files on the remote server, possibly disclosing confidential information.
2. Some of the programs contained in the correction instructions have a vulnerability that allows a malicious user to potentially write arbitrary files on the remote server, possibly corrupting data or altering system behavior.
References
Full note on SAP: SAP Support Launchpad note 1620133
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
