Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Directory Traversal in Payroll Belgium PY-BE, SAP security note 1598152

SAP Note 1598152

SAP security note 1598152, "Directory Traversal in Payroll Belgium PY-BE". Below are the symptom, SAP recommended solution and the affected software components.

ComponentPayroll Belgium (PY-BE)

Description

Symptom

The Payroll Belgium component contains a vulnerability that allows a malicious user to perform directory traversal, potentially reading arbitrary files and disclosing confidential information.

In Payroll Belgium, the system fails to correctly validate the file path used to reference files read from the remote server. This flaw enables a malicious user to manipulate the program to access arbitrary files on the system, leading to potential disclosure of sensitive information.

Solution

To address this vulnerability, implement the necessary corrections using the Note Assistant or by importing the relevant Support Package into your SAP system.

Steps to apply corrections manually:

  • Create logical file path HR_BE_FILE_PATH: navigate to IMG activity "Cross-Client Maintenance of File Names and Paths" (SAP NetWeaver -> Application Server -> System Administration -> Platform-Independent File Names) or use transaction FILE. Insert a new entry HR_BE_FILE_PATH in the "Logical File Path Definition" node and save. Double-click "Assignment of Physical Paths to Logical Path" and maintain entries according to your operating system and the desired physical path.
  • Create logical file name HR_BE_UPLOAD_FILE_DMFA: within the same IMG activity or transaction FILE, insert a new entry HR_BE_UPLOAD_FILE_DMFA in the "Logical File Name Definition, Cross-Client" node, with name "File for uploading in DMFA Report", data format DIR, application area HR, logical path HR_BE_FILE_PATH. Save the changes.

References

Affected components

  • SAP_HR: 46B, 46C
  • SAP_HRCBE: 470, 500, 600, 604

Full note on SAP: SAP Support Launchpad note 1598152

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More