SAP Security Note
Medium priority
SAP security note 1583685, "Potential disclosure of persisted data in CRM-PCF", is a note released on 08.04.2014. Below are the symptom, SAP recommended solution and references.
Description
Symptom
An attacker can exploit CRM-PCF and CA-GTF-PCF by using specially crafted inputs to modify database commands, resulting in the retrieval of additional information persisted by the system.
Solution
Implement the correction instructions attached to this note.
Reason and prerequisites
The issue arises from an SQL injection vulnerability. The vulnerable code constructs an SQL statement that includes strings manipulable by an attacker. This manipulated statement can then be used to extract data from the database.
Security Note 1494284 contains correction instructions which are erroneous. Implementing Security Note 1494284 is a prerequisite for applying this note.
References
- SAP Note 1494284 – XSS: Unauthorized modification of stored content
- SAP Note 1595869 – SAP CRM 7.0 SP-Stack 10 – Release Information Note
- SAP Note 1595868 – SAP CRM 2007 – SP-Stack 10
- SAP Note 1661838 – Unauthorized modification of stored content in CA-GTF-PCF
- SAP Note 1708015 – TOKEN_NOT_FOUND error in PCUI applications
Full note on SAP: SAP Support Launchpad note 1583685
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



