SAP security note 1517832, "HCM: Potential Directory Traversal in Payroll Russia PY-RU" Below are the symptom, reason and prerequisites, SAP recommended solution, references and affected software components.
Description
Symptom
Potential Directory Traversal in PY-RU
Solution
- Implement SAP Security Note 1516824 if you are on a support package level which does not include this note.
- Please refer to SAP Security Note 1497003 for additional information.
Reason and prerequisites
The programs contained in the correction instructions of SAP Security Note 1516824 contain vulnerabilities through which a malicious user can potentially read arbitrary files on the remote server, possibly disclosing confidential information. Some of the programs contained in the correction instructions 1516824 contain a vulnerability through which a malicious user can potentially write arbitrary files on the remote server, possibly corrupting data or altering system behavior.
References
Affected components
- HR-CIS (46C)
- SAP_HRCRU (600 to 604)
- HR-CEECRU (101_470 to 106_500)
Full note on SAP: SAP Support Launchpad note 1517832
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



