Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

HCM Potential Directory Traversal Internat. Payroll PY-XX, SAP security note 1507935

SAP Note 1507935

SAP security note 1507935, "Potential Directory Traversal in Payroll PY-XX". Below are the symptom and SAP recommended solution.

Description

Symptom

Potential Directory Traversal in PY-XX.

Solution

Refer to SAP Note 1497003 for additional information and instructions. The corrections from this note are a prerequisite for implementing Note 1507935. Preparations on the application side have been provided with SAP Note 1506219. Implement the corrections from this note as a prerequisite.

The following logical file names have been created to enable the validation of physical file names:

  • HR_XX_DIR_B2AFILE – Report H99_B2AFILE
  • HR_XX_DIR_RPUFCP01 – Report RPUFCP01
  • HR_XX_DIR_RHMOVE40 – Report RHMOVE40
  • HR_XX_DIR_RH_CALL_ORGDISPLAY – Function Module RH_CALL_ORGDISPLAY

Reason and prerequisites

The programs contained in the correction instructions have vulnerabilities that allow a malicious user to potentially read arbitrary files on the remote server, which may disclose confidential information. Additionally, some programs contain vulnerabilities that allow a malicious user to write arbitrary files on the remote server, potentially corrupting data or altering system behavior.

References

Full note on SAP: SAP Support Launchpad note 1507935

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More