Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Directory Traversal in PY-AU-CE, SAP security note 1605281

SAP Note 1605281

SAP security note 1605281, "Directory Traversal in PY-AU-CE", is a note. Below are the symptom and SAP recommended solution.

Description

Symptom

PY-AU-CE: Potential Directory Traversal in RPCPBSQ0_CE

Solution

Refer to Note 1497003 for additional information and instructions. The corrections from this note are a prerequisite for implementing this note.

Logical File Name Used in this Solution:

  • Logical filename: HR_AU_DIR_ATO_FILE_NAME
  • Program Using this logical filename: RPCPBSQ0_CE
  • Logical File Path Used in this Solution: HR_AU_FILENAME

Reason and prerequisites

1. The programs included in the correction instructions contain vulnerabilities that allow a malicious user to potentially read arbitrary files on the remote server, possibly disclosing confidential information.

2. Some programs in the correction instructions contain a vulnerability that allows a malicious user to potentially write arbitrary files on the remote server, possibly corrupting data or altering system behavior.

References

Full note on SAP: SAP Support Launchpad note 1605281

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More