Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Missing Authorization Check,Deleting Temp pages in PLM-CFO, SAP security note 1510725

SAP Note 1510725
SAP Security Note
Medium priority

SAP security note 1510725, "Missing Authorization Check, Deleting Temp pages in PLM-CFO", is a program error note released on September 13, 2011. Below are the symptom, SAP recommended solution and the affected software components.

ComponentProduct Lifecycle Management > Collaboration Folders
CategoryProgram error
PriorityCorrection with medium priority
TypeSAP Security Note
Version4
StatusReleased for Customer
Released onSeptember 13, 2011

Description

Symptom

  1. An authenticated user can use functionality of PLM-CFO to which access should be restricted. This can potentially result in an escalation of privileges.
  2. A malicious user can discover information relating to user information in PLM-CFO. This information could be used to allow the malicious user to specialize their attacks against user information and PLM-CFO.

Solution

For Symptom 1: Please apply the correction instructions provided in the note.

For Symptom 2: Follow the given manual instructions.

Prerequisite Notes:

  • Note 1466863 for cFolder releases 3.1, 4.0, and 4.5.
  • Note 1496707 for cFolder release 5.0.

Reason and prerequisites

  1. PLM-CFO lacks permission checks for an authenticated user’s authorization to access some of its functionality. This may result in undesired system behavior.
  2. There are test pages on the PLM-CFO which are not needed for productive use. Test pages can contain debug code or code which was only used for testing purposes without a concern for security. Often these pages are no longer maintained, so errors will not get fixed.

Affected components

  • CPROJECTS: 310_620 to 310_640
  • CPRXRPM: 400 to 400
  • CPRXRPM: 450_700 to 450_700
  • CPRXRPM: 500_702 to 500_702

Full note on SAP: SAP Support Launchpad note 1510725

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More