SAP security note 1519001, "Unauthorized usage of application functionality in PLM-CFO", is a program error note released on 14.12.2010. Below are the symptom and SAP recommended solution.
Description
Symptom
A malicious user can trigger functionality in PLM-CFO without authentication and authorization. When performing a mass download, the file is successfully downloaded, but an extra popup for an error appears.
Solution
Please implement the following correction instructions.
Reason and prerequisites
PLM-CFO executes certain functions by referencing specific URLs. An attacker can trick an authenticated user's browser into making a request with a specific URL and parameters, causing the function to execute with the user's privileges.
Potential attack vectors include:
- Cross Site Scripting (XSS) to trigger the exploit.
- Presenting a malicious link for the victim to click.
Full note on SAP: SAP Support Launchpad note 1519001
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



