SAP Security Note
Medium priority
SAP security note 1510725, "Missing Authorization Check, Deleting Temp pages in PLM-CFO", is a program error note released on September 13, 2011. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
- An authenticated user can use functionality of PLM-CFO to which access should be restricted. This can potentially result in an escalation of privileges.
- A malicious user can discover information relating to user information in PLM-CFO. This information could be used to allow the malicious user to specialize their attacks against user information and PLM-CFO.
Solution
For Symptom 1: Please apply the correction instructions provided in the note.
For Symptom 2: Follow the given manual instructions.
Prerequisite Notes:
- Note 1466863 for cFolder releases 3.1, 4.0, and 4.5.
- Note 1496707 for cFolder release 5.0.
Reason and prerequisites
- PLM-CFO lacks permission checks for an authenticated user’s authorization to access some of its functionality. This may result in undesired system behavior.
- There are test pages on the PLM-CFO which are not needed for productive use. Test pages can contain debug code or code which was only used for testing purposes without a concern for security. Often these pages are no longer maintained, so errors will not get fixed.
Affected components
- CPROJECTS: 310_620 to 310_640
- CPRXRPM: 400 to 400
- CPRXRPM: 450_700 to 450_700
- CPRXRPM: 500_702 to 500_702
Full note on SAP: SAP Support Launchpad note 1510725
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
