Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Directory traversal in PY-SE, SAP security note 1769611

SAP Note 1769611

SAP security note 1769611, "Directory Traversal Vulnerability in PY-SE". Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

A directory traversal vulnerability has been identified in the PY-SE component of SAP Payroll for Sweden. This vulnerability allows an attacker to write arbitrary files to the remote server, which could lead to data corruption or alterations in system behavior.

Exploiting this vulnerability can enable unauthorized file manipulation on the server, potentially compromising data integrity and system functionality.

Solution

To address this issue, refer to SAP Note 1497003 for additional information and implementation instructions. The corrections from this note are a prerequisite for applying the necessary fixes outlined in this note.

  • Install the required HR support packages, ensuring the correction instructions from SAP Note 1497003 are implemented.
  • Configure the logical file path HR_SE_DIR_DOWNLOAD via IMG activity SAP NetWeaver > Application Server > System Administration > Platform-Independent File Names, or transaction FILE, assigning the physical path for your operating system.
  • Repeat the same steps to create the logical file path HR_SE_DIR_UPLOAD.
  • Maintain logical file names: HR_SE_DIR_DOWNLOAD (Global download directory for Sweden, data format DIR, application area HR) and HR_SE_DIR_UPLOAD (Global upload directory for Sweden, data format DIR, application area HR).

References

Affected components

  • SAP_HR 46C
  • SAP_HRCSE 470, 500, 600, 604

Full note on SAP: SAP Support Launchpad note 1769611

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More