SAP Security Note
Medium priority
SAP security note 1768943, “Potential Directory Traversal in PY-IT”, is a note released on 12.03.2013. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
PY-IT contains a vulnerability that allows an attacker to perform directory traversal, enabling the writing of arbitrary files to the remote server. This can potentially corrupt data or alter system behavior.
Solution
- Implement Correction Instructions: Use the Note Assistant (SNOTE) to apply the correction instructions provided in this SAP Note. Detailed correction instructions are available here for SAP_HRCIT and here for SAP_HR.
Reason and prerequisites
PY-IT does not correctly validate the file path for user-submitted files. This flaw allows an attacker to overwrite data in the remote system.
CVSS
Score 0
Affected components
- SAP_HR: Releases 31I, 40B, 45B, 46B, 46C
- SAP_HRCIT: Releases 470, 500, 600, 604
Full note on SAP: SAP Support Launchpad note 1768943
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
