SAP Security Note
High priority
SAP security note 1598592, "Directory traversal in RPLLAWC1", is a program error note released on 10.01.2012. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
RPLLAWC1 contains a vulnerability through which a malicious user can potentially write arbitrary files on the remote server, possibly corrupting data or altering system behavior.
Solution
The report RPLLAWC1 (HR-CH: Wage Statement for Tax Return) is obsolete and can no longer be called after you implement this note.
- Import the HR Support Package specified for your release or
- Implement the relevant correction instructions.
Reason and prerequisites
RPLLAWC1 fails to correctly validate the path to which a user-submitted file is written. As a result, a malicious user can potentially overwrite data in the remote system.
CVSS
Score 0
References
This note refers to
Affected components
- SAP_HR (46C)
- SAP_HRCCH (470, 500, 600, 604)
Full note on SAP: SAP Support Launchpad note 1598592
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
