SAP Security Note
High priority
SAP security note 1510724, “Potential information disclosure relating to password”, is a program error note released on 14.12.2010. Below are the symptom, reason and prerequisites, the SAP recommended solution and the affected software components.
Description
Symptom
A malicious user can discover information relating to passwords used in PLM-CFO. This information could be exploited to specialize attacks against users and PLM-CFO.
Solution
Please apply the correction instructions to resolve the issue.
Reason and prerequisites
Information such as user passwords can be discovered through the use of PLM-CFO. This information can potentially be used by a malicious user to further target user details or cFolders.
Affected components
- CPROJECTS 310_620 to 310_640
- CPRXRPM 400
- CPRXRPM 450_700
- CPRXRPM 500_702
Full note on SAP: SAP Support Launchpad note 1510724
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
