SAP security note 1531268, "Potential modification of persisted data in OpenPS4MSP". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
A malicious user can exploit OpenPS and use specially crafted inputs to modify database commands, resulting in the modification of data persisted by the system.
Solution
Please follow the following steps to download and install OpenPS 4.0 SP3 Patch01:
- In SAP Service Marketplace, go to the SAP Support Portal.
- Click on "Software Downloads," and then on "Support Packages and Patches."
- In the left navigation pane, under "Support Packages and Patches," choose "Support Packages and Patches – Entry by Application Group."
- On the main page, a list of links is displayed. Choose "Supplementary Components for Cross Industry Solutions."
- Follow these links in sequence: "Project Management", "OPENPS FOR MS PROJECT", "OPENPS FOR MS PROJECT 4.0", "OPENPS FOR MS PROJECT 4.0", "Win32".
- Download the latest available patch.
- Save the ZIP file into a local folder and run the "Setup.exe" file.
For security reasons, during logon, the system does not support a few special characters for user name and system details. Note that this restriction applies to a few characters only and does not apply to ALL special characters. To proceed with the logon, it is recommended to use alphanumeric characters.
Review the documentation available in the combinational guide regarding installations and upgrades. Consult the related notes for this release, including the FAQ and Restriction Note.
When uninstalling OpenPS, the system does not delete the OpenPS4MSP folder created under Program -> Files -> SAP -> OpenPS4MSP. It also does not delete the following files containing user information: Windows XP: Documents and Settings -> <user name> -> OpenPS4MSP; Windows Vista: Users -> <user name> -> OpenPS4MSP. If these files are deleted, the user will have to reconfigure the preferences every time OpenPS is upgraded, as these folders store user preferences and options.
Reason and prerequisites
The problem is caused by an SQL injection vulnerability. The code composes an SQL statement that contains strings that can be altered by a malicious user. The manipulated SQL statement can then be used to modify information in the database.
CVSS
Score 0
References
- OpenPS 4.0 SP03 Release Information Note
- OpenPS 4.0 SP02 and SP02 Patch 01 – Release Information Note
- Trouble Shooting Note on OpenPS 4.0 for Microsoft Project
- Restriction note on OpenPS4.0 for Microsoft Project
- FAQ note on OpenPS4.0 for Microsoft Project
- OpenPS 4.0 Release Information Note
- OpenPS4MSP: Version 2.02
- OpenPS4MSP 2.0: Release History
Affected components
- OPENPS_MSPRO: From 4.0 to 4.0
Full note on SAP: SAP Support Launchpad note 1531268
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



