SAP Security Note
Medium priority
SAP security note 2260876, "Multiple vulnerabilities in LM Configuration Wizard", is a program error note released on 10.05.2016. Below are the symptom and SAP recommended solution.
Description
Symptom
Multiple security vulnerabilities have been discovered in the Central Technical Configuration application.
- Cross Site Scripting (XSS): the application does not sufficiently encode user-controlled inputs, resulting in a Cross-Site Scripting (XSS) vulnerability.
- Missing Authorization Check: the application does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.
Solution
Implement the recommended support package and patches.
Reason and prerequisites
This note is applicable only when the following LMCTC versions are used:
- LM CONFIGURATION WIZARD 7.10 SP19 to 21
- LM CONFIGURATION WIZARD 7.11 SP14 to 16
- LM CONFIGURATION WIZARD 7.20 SP09
- LM CONFIGURATION WIZARD 7.30 SP13,14,16
- LM CONFIGURATION WIZARD 7.31 SP11 to 19
- LM CONFIGURATION WIZARD 7.40 SP06 to 14
- LM CONFIGURATION WIZARD 7.50 SP00 to 05
CVSS
Score 6.1 Vector: AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Score 5.3
References
Full note on SAP: SAP Support Launchpad note 2260876
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




