SAP security note 1503108, "Directory traversal in programs PKRT_DEPS_ANALYSIS*". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Programs PKRT_DEPS_ANALYSIS and PKRT_DEPS_ANALYSIS_PREPARE contain a vulnerability that allows a malicious user to write arbitrary files on the remote server. This can potentially corrupt data or alter system behavior. These programs are internal analysis tools not intended for productive system use and are not executed from any standard transaction.
Solution
Install the recommended support package to disable the vulnerable programs PKRT_DEPS_ANALYSIS and PKRT_DEPS_ANALYSIS_PREPARE.
Reason and prerequisites
The vulnerability arises because PKRT_DEPS_ANALYSIS and PKRT_DEPS_ANALYSIS_PREPARE fail to correctly validate the file name specified by a user before writing to and reading from that file. As a result, an attacker can overwrite data on the remote system.
Affected components
- SAP_BASIS: Versions 711, 720, 730 (Basis Components > ABAP Runtime Environment – ABAP Language Issues Only > Syntax, Compiler, Runtime)
Full note on SAP: SAP Support Launchpad note 1503108
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



