SAP security note 1731835, "Unauthorized modification of displayed content in PPM-PFM", is a note. Below are the symptom and SAP recommended solution.
Description
Symptom
PPM-PFM allows unauthorized modification of displayed content and can expose authentication information from other users.
Solution
Implement the corrections attached with this note.
Reason and prerequisites
The issue originates from CL_RPM_FILE_HTTP_HANDLER within PPM-PFM, which does not sufficiently encode input and output parameters. This results in a reflected cross-site scripting vulnerability, enabling attackers to:
- Non-permanently deface or modify displayed content on the website.
- Steal user authentication information, such as session data.
- Impersonate users, including administrators, potentially compromising application security entirely.
References
Full note on SAP: SAP Support Launchpad note 1731835
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
