SAP security note 1507935, "Potential Directory Traversal in Payroll PY-XX". Below are the symptom and SAP recommended solution.
Description
Symptom
Potential Directory Traversal in PY-XX.
Solution
Refer to SAP Note 1497003 for additional information and instructions. The corrections from this note are a prerequisite for implementing Note 1507935. Preparations on the application side have been provided with SAP Note 1506219. Implement the corrections from this note as a prerequisite.
The following logical file names have been created to enable the validation of physical file names:
- HR_XX_DIR_B2AFILE – Report H99_B2AFILE
- HR_XX_DIR_RPUFCP01 – Report RPUFCP01
- HR_XX_DIR_RHMOVE40 – Report RHMOVE40
- HR_XX_DIR_RH_CALL_ORGDISPLAY – Function Module RH_CALL_ORGDISPLAY
Reason and prerequisites
The programs contained in the correction instructions have vulnerabilities that allow a malicious user to potentially read arbitrary files on the remote server, which may disclose confidential information. Additionally, some programs contain vulnerabilities that allow a malicious user to write arbitrary files on the remote server, potentially corrupting data or altering system behavior.
References
- SAP Note 1591557 – Potential directory traversal in utility report RPUOTFL0
- SAP Note 1542428 – ABAP runtime error CALL_FUNCTION_CONFLICT_GEN_TYP
- SAP Note 1533996 – HCM: Potential Directory Traversal in Payroll Switzerland
- SAP Note 1517831 – Potential Directory Traversal in SAP HCM Payroll NPO
- SAP Note 1517830 – HCM: Potential Directory Traversal in Payroll GB PS
- SAP Note 1517828 – HCM: Potential Directory Traversal in Payroll Singapore PY-SG
- SAP Note 1517825 – HCM: Potential Directory Traversal in Payroll Canada PY-CA
- SAP Note 1510789 – Travel Expenses: Potential directory traversal
- SAP Note 1507936 – HCM: Potential Directory Traversal in German Payroll PY-DE
- SAP Note 1506219 – Checkman correction
- SAP Note 1497003 – Potential directory traversals in applications
Full note on SAP: SAP Support Launchpad note 1507935
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
