Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

HCMPotential Directory Traversal in Payroll GB PS, SAP security note 1517830

SAP Note 1517830SAP Security NoteHigh priority

SAP security note 1517830, "HCM: Potential Directory Traversal in Payroll GB PS", is released on December 14, 2010. Below are the symptom, SAP recommended solution, reason and prerequisites, references and the affected software components.

ComponentPayroll > United Kingdom > Public Sector (PY-GB-PS)
PriorityCorrection with high priority
TypeSAP Security Note
Version1
StatusReleased for Customer
Released onDecember 14, 2010

Description

Symptom

Potential Directory Traversal in PY-GB-PS.

Solution

Please refer to Note 1497003 for additional information and instructions. The corrections from Notes 1497003, 1507935, and 1516365 are prerequisites for the implementation of this note.

Reason and prerequisites

The programs contained in the correction instructions of Note 1516365 contain vulnerabilities that allow a malicious user to potentially read arbitrary files on the remote server, possibly disclosing confidential information. Some programs in the correction instructions of Note 1516365 have a vulnerability that allows a malicious user to potentially write arbitrary files on the remote server, possibly corrupting data or altering system behavior.

References

Affected components

  • HR-PS (462A)
  • SAP_HRCGB (470, 500, 600, 604)

Full note on SAP: SAP Support Launchpad note 1517830

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More