SAP Security Note
High priority
SAP security note 1598285, "Directory Traversal in Payroll Belgium PY-BE", is a note released on August 9, 2011. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
The Payroll Belgium (PY-BE) module contains a vulnerability that allows a malicious user to perform directory traversal, potentially writing arbitrary files on the remote server. This can lead to data corruption or alteration of system behavior. Additionally, improperly maintained filenames can cause short dumps in specific cases.
Solution
Please refer to SAP Note 1497003 for additional information.
Create Logical File Path HR_BE_FILE_PATH_DOWN: navigate to the IMG activity "Cross-Client Maintenance of File Names and Paths" (SAP NetWeaver -> Application Server -> System administration -> Platform-Independent File Names) or use transaction FILE. Insert a new entry HR_BE_FILE_PATH_DOWN in the "Logical File Path Definition" node and save it. Double-click "Assignment of Physical Paths to Logical Path" for the new entry and maintain entries according to your operating system and the desired physical path.
Create Logical File Name HR_BE_DOWNLOAD_FILE_PD: navigate to the same IMG activity or use transaction FILE. Insert a new entry HR_BE_DOWNLOAD_FILE_PD in the "Logical File Name Definition, Cross-Client" node and maintain the following values:
- Logical File:
HR_BE_DOWNLOAD_FILE_PD - Name: File created via Pensioners Declaration (download)
- Data Format: DIR
- Applicat. Area: HR
- Logical Path:
HR_BE_FILE_PATH_DOWN
Reason and prerequisites
In Payroll Belgium, the system fails to correctly validate the path where a user-submitted file is written. This oversight enables a malicious user to overwrite data on the remote system.
References
Affected components
- SAP_HR: 46B, 46C
- SAP_HRCBE: 470, 500, 600, 604
Full note on SAP: SAP Support Launchpad note 1598285
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
