SAP security note 1786809, “Directory Traversal in PY-NO”, is a note released on September 10, 2013. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
PY-NO fails to correctly validate file paths used to reference or write files on the remote server. An attacker can exploit this to access or overwrite arbitrary files.
Exploiting this vulnerability can allow unauthorized access to sensitive files, potential data corruption, or alteration of system behavior, posing significant security risks to the affected SAP systems.
Solution
Implement the corrections from SAP Note 1497003 – Potential directory traversals in applications.
- Create logical file path definitions HR_NO_DIR_DOWNLOAD (global download directory for Norway) and HR_NO_DIR_UPLOAD (global upload directory for Norway) using the IMG activity “Cross-Client Maintenance of File Names and Paths” under SAP NetWeaver, Application Server, System administration, Platform-Independent File Names, or transaction FILE.
- Assign physical paths corresponding to the logical file names based on your operating system to ensure secure separation of data for different users and programs.
Affected components
- SAP_HRCNO (470, 500, 600, 604)
Full note on SAP: SAP Support Launchpad note 1786809
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
