Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Cross Site Scripting (XSS) FPM_TEST_CATALG possible, SAP security note 1483601

SAP Note 1483601
High

SAP security note 1483601, "Cross Site Scripting (XSS) FPM_TEST_CATALG possible", is a note released on December 14, 2010. Below are the symptom, SAP recommended solution and the affected software components.

ComponentBasis Components > Web Dynpro > Configurable Component > Floorplanmanager (BC-WD-CMP-FPM)
PriorityHigh
StatusReleased for Customer
Released onDecember 14, 2010

Description

Symptom

A reflected Cross-Site Scripting (XSS) vulnerability has been identified in the BSP application FPM_TEST_CATALG. This vulnerability allows malicious users to modify application content without authorization and potentially steal authentication information from other users.

An attacker exploiting this vulnerability could deface or modify displayed content on the website, steal authentication information enabling impersonation of legitimate users, and compromise the application’s security, especially if an administrator’s account is targeted.

Solution

You have two options to address this issue:

  • Wait for the official Support Package that includes the fix once it is available.
  • Immediately delete the BSP application FPM_TEST_CATALG in transaction SE80. This BSP was initially used for testing purposes and is not intended for production environments.

Affected components

  • SAP_ABA 701 to 702
  • SAP_ABA 711 to 730

Full note on SAP: SAP Support Launchpad note 1483601

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More