SAP Security Note
High priority
SAP security note 1599244, "Directory traversal in RPLIKAC1", is a program error note released on 13.03.2012. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
RPLIKAC1 contains a vulnerability through which a malicious user can potentially write arbitrary files on the remote server, possibly corrupting data or altering system behaviour.
Solution
The report RPLIKAC1 (HR-CH: Invalidity Fund – Annual Payroll) is obsolete and can no longer be called after you implement this note.
- Import the HR Support Package specified for your release or implement the relevant correction instructions.
- Create message 034 with the following text: 034: "Program is no longer supported. See Note &1". Procedure for creating messages: Call transaction SE91, enter the message class HRPAYCH01 and choose "Change". Enter the message number 034, choose Enter, and then choose the button for individual maintenance. Enter the correct message text, set the "Self-explanat’y" indicator and save your changes.
- Implement the attached corrections in the report RPLIKAC1.
Reason and prerequisites
RPLIKAC1 fails to correctly validate the path to which a user-submitted file is written. As a result, a malicious user can potentially overwrite data in the remote system.
References
Affected components
- SAP_HR: 46C
- SAP_HRCCH: 470, 500, 600, 604
Full note on SAP: SAP Support Launchpad note 1599244
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




