Medium priority
SAP security note 1517831, "Potential Directory Traversal in SAP HCM Payroll NPO", is a program error note released on 31.10.2018. Below are the symptom and the SAP recommended solution.
Description
Symptom
A potential directory traversal vulnerability exists in SAP HCM Payroll NPO. This vulnerability allows a malicious user to:
- Read arbitrary files on the remote server, potentially disclosing confidential information.
- Write arbitrary files on the remote server, possibly corrupting data or altering system behavior.
Solution
Refer to SAP Note 1497003 for additional information and instructions. The following corrections are prerequisites for implementing this note:
- SAP Note 1497003 – Potential directory traversals in applications
- SAP Note 1507935 – HCM: Potential Directory Traversal Internat. Payroll PY-XX
- SAP Note 1518715 – Quality Enhancements
CVSS
Score 4.3/10 Vector: AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
References
- SAP Note 1518715 – Quality Enhancements
- SAP Note 1507935 – HCM: Potential Directory Traversal Internat. Payroll PY-XX
- SAP Note 1497003 – Potential directory traversals in applications
Full note on SAP: SAP Support Launchpad note 1517831
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



