Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Multiple vulnerabilities in LM Configuration Wizard, SAP security note 2260876

SAP Note 2260876
SAP Security Note
Medium priority

SAP security note 2260876, "Multiple vulnerabilities in LM Configuration Wizard", is a program error note released on 10.05.2016. Below are the symptom and SAP recommended solution.

ComponentBasis Components > Installation Tools (SAP Note 1669327) > Central technical configuration
CategoryProgram error
PriorityMedium priority
TypeSAP Security Note
Version10
StatusReleased for Customer
Released on10.05.2016
LanguageEnglish

Description

Symptom

Multiple security vulnerabilities have been discovered in the Central Technical Configuration application.

  • Cross Site Scripting (XSS): the application does not sufficiently encode user-controlled inputs, resulting in a Cross-Site Scripting (XSS) vulnerability.
  • Missing Authorization Check: the application does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.

Solution

Implement the recommended support package and patches.

Reason and prerequisites

This note is applicable only when the following LMCTC versions are used:

  • LM CONFIGURATION WIZARD 7.10 SP19 to 21
  • LM CONFIGURATION WIZARD 7.11 SP14 to 16
  • LM CONFIGURATION WIZARD 7.20 SP09
  • LM CONFIGURATION WIZARD 7.30 SP13,14,16
  • LM CONFIGURATION WIZARD 7.31 SP11 to 19
  • LM CONFIGURATION WIZARD 7.40 SP06 to 14
  • LM CONFIGURATION WIZARD 7.50 SP00 to 05

CVSS

Score 6.1 Vector: AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Score 5.3

References

Full note on SAP: SAP Support Launchpad note 2260876

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More