Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized Access of document possible in PPM-PFM, SAP security note 1687863

SAP Note 1687863
SAP Security Note
Medium priority

SAP security note 1687863, "Unauthorized Access of document possible in PPM-PFM", is a program error note released on 06.11.2014. Below are the symptom and SAP recommended solution.

ComponentPortfolio and Project Management > Portfolio Management
CategoryProgram Error
PriorityCorrection with Medium Priority
TypeSAP Security Note
Version1
StatusReleased for Customer
Released on06.11.2014
LanguageEnglish

Description

Symptom

This SAP Security Note addresses a vulnerability in the Portfolio and Project Management – Portfolio Management (PPM-PFM) component that allows unauthorized access to documents and potential information leakage through URL parameter manipulation.

Solution

Implement the corrections provided with this SAP Note to address the vulnerability.

Reason and prerequisites

An attacker can exploit PPM-PFM to modify displayed application content without authorization. Specifically, the URL parameter NO_AUTH_CHECK appears to disable authorization checks, allowing malicious users to bypass authority checks by appending this parameter to URLs.

Additionally, CL_RPM_FILE_HTTP_HANDLER within PPM-PFM insufficiently encodes input parameters, leading to a reflected cross-site scripting (XSS) vulnerability. This vulnerability can be used to deface web content, steal user authentication information, and impersonate users, including administrators, thereby compromising application security.

An attacker exploiting this vulnerability can:

  • Modify and deface displayed content.
  • Steal authentication information from legitimate users.
  • Impersonate users, potentially gaining full administrative access.

References

Full note on SAP: SAP Support Launchpad note 1687863

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More