SAP security note 1620072, “Directory traversal in PY-FR-IE”. Below are the symptom and SAP recommended solution.
Description
Symptom
The directory traversal vulnerability in PY-FR-IE allows a malicious user to potentially write arbitrary files on the remote server. This can lead to data corruption or alteration of system behavior.
Solution
Refer to SAP Note 1497003 for additional information and detailed instructions. Implementing the corrections from SAP Note 1497003 is a prerequisite for applying SAP Note 1620072.
Steps to implement:
- Support Packages: apply the relevant HR Support Packages as listed below, or implement the correction instructions provided in SAP Note 1497003.
- Define Aliases: after implementing the note, define aliases for the logical file name HR_FR_P06I_IN in view V_FILEALIA. Use the provided parameters (<PARAM_1> for program name and <PARAM_2> for file type – TEDC or TEDI) when building the physical file name.
Reason and prerequisites
The program described in the correction instructions contains a vulnerability that can be exploited to write arbitrary files on the remote server. This could result in data corruption or changes to system behavior.
References
This note refers to
Full note on SAP: SAP Support Launchpad note 1620072
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




