SAP security note 1533996, "Potential Directory Traversal in Payroll Switzerland". Below are the symptom and SAP recommended solution.
Description
Symptom
Potential Directory Traversal in PY-CH.
Solution
- Implement note 1533995 if you are on a support package level that does not include this note.
- Please refer to note 1497003 for additional information.
Reason and prerequisites
The programs contained in the correction instructions of note 1533995 contain vulnerabilities through which a malicious user can potentially read arbitrary files on the remote server, possibly disclosing confidential information.
Some of the programs contained in the correction instructions 1533995 contain a vulnerability through which a malicious user can potentially write arbitrary files on the remote server, possibly corrupting data or altering system behavior.
Full note on SAP: SAP Support Launchpad note 1533996
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




