Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Directory traversal in PY-FR-IE, SAP security note 1598851

SAP Note 1598851
SAP Security Note
High priority

SAP security note 1598851, "Directory Traversal in PY-FR-IE", is released on 08.11.2011. Below are the symptom and SAP recommended solution.

ComponentPayroll > France > Interface to External Payroll Systems
PriorityCorrection with High Priority
TypeSAP Security Note
Version2
StatusReleased for Customer
Released on08.11.2011

Description

Symptom

The PY-FR-IE component contains a vulnerability that allows a malicious user to perform directory traversal, potentially writing arbitrary files on the remote server. This can lead to data corruption or alteration of system behavior.

Impacted programs:

  • RPB015FI
  • RPB435FI
  • RPB436FI
  • RPDADVFI
  • RPDDICFI
  • RPDOWNFI
  • RPFEDMFI
  • RPIJSSFI
  • RPLOADFI
  • RPRP55FI
  • RPRP56FI
  • RPRP58FI
  • RPSENDFI
  • RPTEDIFI
  • RPTMSEFI
  • RPTVLOFI

Solution

Implement the HR Support Packages listed below or follow the correction instructions provided in this note. After applying the corrections, only file paths defined in the TEDC customizing will be accepted.

Reason and prerequisites

The vulnerability exists because PY-FR-IE fails to properly validate the file path, allowing malicious users to overwrite data on the remote system.

Full note on SAP: SAP Support Launchpad note 1598851

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More