SAP security note 1517830, "HCM: Potential Directory Traversal in Payroll GB PS", is released on December 14, 2010. Below are the symptom, SAP recommended solution, reason and prerequisites, references and the affected software components.
Description
Symptom
Potential Directory Traversal in PY-GB-PS.
Solution
Please refer to Note 1497003 for additional information and instructions. The corrections from Notes 1497003, 1507935, and 1516365 are prerequisites for the implementation of this note.
Reason and prerequisites
The programs contained in the correction instructions of Note 1516365 contain vulnerabilities that allow a malicious user to potentially read arbitrary files on the remote server, possibly disclosing confidential information. Some programs in the correction instructions of Note 1516365 have a vulnerability that allows a malicious user to potentially write arbitrary files on the remote server, possibly corrupting data or altering system behavior.
References
- 1516365 – HRGB: Quality improvements to GB Reports
- 1507935 – HCM: Potential Directory Traversal Internat. Payroll PY-XX
- 1497003 – Potential directory traversals in applications
Affected components
- HR-PS (462A)
- SAP_HRCGB (470, 500, 600, 604)
Full note on SAP: SAP Support Launchpad note 1517830
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



