SAP security note 1694061, "Unauthorized Modification of Displayed Content in PLM-CFO(6)", is a note released on 08.05.2012. Below are the symptom, SAP recommended solution and affected software components.
Description
Symptom
The PLM-CFO can be abused by a malicious user, allowing unauthorized modification of displayed application content and potential theft of authentication information from legitimate users.
Solution
Implement the program corrections detailed in the Correction Instruction tab of this note. Follow the instructions to apply the necessary patches to your system.
Reason and prerequisites
Pages within the PLM-CFO do not sufficiently encode input and output parameters, resulting in a reflected Cross-Site Scripting (XSS) vulnerability. This flaw can be exploited to:
- Deface or Modify Content: Non-permanently alter displayed content on the website.
- Steal Authentication Information: Capture data related to a user's session to impersonate the user and access information with the same privileges. If an administrator is impersonated, it may lead to a full compromise of the application's security.
Prerequisite notes:
- 1661780
- 1694056
- 1694057
- 1694059
- 1694060
References
This note refers to
- 1694081 – Unauthorized modification of displayed content in PLM-CFO(14)
- 1694080 – Unauthorized modification of displayed content in PLM-CFO(13)
- 1694078 – Unauthorized modification of displayed content in PLM-CFO(12)
- 1694077 – Unauthorized modification of displayed content in PLM-CFO(11)
- 1694076 – Unauthorized modification of displayed content in PLM-CFO(10)
- 1694075 – Unauthorized modification of displayed content in PLM-CFO(9)
- 1694074 – Unauthorized modification of displayed content in PLM-CFO(8)
- 1694062 – Unauthorized modification of displayed content in PLM-CFO(7)
- 1694060 – Unauthorized modification of displayed content in PLM-CFO(5)
- 1694059 – Unauthorized modification of displayed content in PLM-CFO(4)
- 1694057 – Unauthorized modification of displayed content in PLM-CFO(3)
- 1694056 – Unauthorized modification of displayed content in PLM-CFO(2)
- 1661780 – Unauthorized modification of displayed content in PLM-CFO(1)
Affected components
- CPROJECTS: Versions 310_620 to 310_640
- CPRXRPM: 400, 450_700, 500_702
Full note on SAP: SAP Support Launchpad note 1694061
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
