Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized modification of displayed content in PLM-CFO(6), SAP security note 1694061

SAP Note 1694061SAP Security NoteHigh priority

SAP security note 1694061, "Unauthorized Modification of Displayed Content in PLM-CFO(6)", is a note released on 08.05.2012. Below are the symptom, SAP recommended solution and affected software components.

ComponentProduct Lifecycle Management > Collaboration Folders (PLM-CFO)
PriorityHigh priority
TypeSAP Security Note
Version2
StatusReleased for Customer
Released on08.05.2012
LanguageEnglish

Description

Symptom

The PLM-CFO can be abused by a malicious user, allowing unauthorized modification of displayed application content and potential theft of authentication information from legitimate users.

Solution

Implement the program corrections detailed in the Correction Instruction tab of this note. Follow the instructions to apply the necessary patches to your system.

Reason and prerequisites

Pages within the PLM-CFO do not sufficiently encode input and output parameters, resulting in a reflected Cross-Site Scripting (XSS) vulnerability. This flaw can be exploited to:

  • Deface or Modify Content: Non-permanently alter displayed content on the website.
  • Steal Authentication Information: Capture data related to a user's session to impersonate the user and access information with the same privileges. If an administrator is impersonated, it may lead to a full compromise of the application's security.

Prerequisite notes:

  • 1661780
  • 1694056
  • 1694057
  • 1694059
  • 1694060

References

Affected components

  • CPROJECTS: Versions 310_620 to 310_640
  • CPRXRPM: 400, 450_700, 500_702

Full note on SAP: SAP Support Launchpad note 1694061

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More