SAP Security Note
High priority
SAP security note 1555371, “Update #1 to Security Note 1466863”, is released on 06.03.2012. Below are the symptom and SAP recommended solution.
Description
Symptom
Correction instructions provided for the vulnerability XSS addressed in Security Note 1466863 must be corrected for the following releases:
- cFolder 4.5: till SAPK-45010INCPRXRPM
- cFolder 4.0: till SAPK-40019INCPRXRPM
- cFolder 3.1: till SAPK-31219INCPROJECT
Solution
Please apply the correction instruction to resolve the issue.
For release cFolders 5.0, note 1593294 has to be implemented.
Reason and prerequisites
Security Notes 1466863 contains correction instructions which are erroneous. The implementation of Security Notes 1466863 is a prerequisite for applying this note.
References
- 1666244 – cFolders: Composite SAP Note – Security
- 1593294 – Update #1 to Security Note 1496707
- 1543703 – Redlining is not working
- 1466863 – Unauthorized modification of displayed content in PLM-CFO.
Full note on SAP: SAP Support Launchpad note 1555371
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
