Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Potential directory traversal in PY-IT, SAP security note 1768943

SAP Note 1768943
SAP Security Note
Medium priority

SAP security note 1768943, “Potential Directory Traversal in PY-IT”, is a note released on 12.03.2013. Below are the symptom, SAP recommended solution and the affected software components.

ComponentPayroll > Italy (PY-IT)
PriorityCorrection with medium priority
TypeSAP Security Note
Version3
StatusReleased for Customer
Released on12.03.2013
LanguageEnglish

Description

Symptom

PY-IT contains a vulnerability that allows an attacker to perform directory traversal, enabling the writing of arbitrary files to the remote server. This can potentially corrupt data or alter system behavior.

Solution

  • Implement Correction Instructions: Use the Note Assistant (SNOTE) to apply the correction instructions provided in this SAP Note. Detailed correction instructions are available here for SAP_HRCIT and here for SAP_HR.

Reason and prerequisites

PY-IT does not correctly validate the file path for user-submitted files. This flaw allows an attacker to overwrite data in the remote system.

CVSS

Score 0

Affected components

  • SAP_HR: Releases 31I, 40B, 45B, 46B, 46C
  • SAP_HRCIT: Releases 470, 500, 600, 604

Full note on SAP: SAP Support Launchpad note 1768943

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More