Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized modification of displayed content in PLM-CFO(4), SAP security note 1694059

SAP Note 1694059SAP Security NoteHigh Priority

SAP security note 1694059, "Unauthorized Modification of Displayed Content in PLM-CFO", is a note released on May 8, 2012. Below are the symptom, SAP recommended solution and affected software components.

ComponentProduct Lifecycle Management > Collaboration Folders (PLM-CFO)
PriorityHigh Priority
TypeSAP Security Note
StatusReleased for Customer
Released onMay 8, 2012

Description

Symptom

A reflected Cross Site Scripting (XSS) vulnerability has been identified in PLM-CFO. This issue allows malicious users to modify displayed application content without authorization and potentially steal authentication information from legitimate users. In cases where an administrator is impersonated, it could lead to a full compromise of the application's security.

Solution

Implement the program corrections detailed in the Correction Instructions tab of this SAP Security Note.

Reason and prerequisites

The vulnerability arises because pages within PLM-CFO do not sufficiently encode input and output parameters, resulting in the XSS issue.

Prerequisite notes:

Affected components

  • CPROJECTS: Versions 310_620 to 310_640
  • CPRXRPM: Versions 400, 450_700, and 500_702

Full note on SAP: SAP Support Launchpad note 1694059

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More