SAP Security Note
Medium priority
SAP security note 1687863, "Unauthorized Access of document possible in PPM-PFM", is a program error note released on 06.11.2014. Below are the symptom and SAP recommended solution.
Description
Symptom
This SAP Security Note addresses a vulnerability in the Portfolio and Project Management – Portfolio Management (PPM-PFM) component that allows unauthorized access to documents and potential information leakage through URL parameter manipulation.
Solution
Implement the corrections provided with this SAP Note to address the vulnerability.
Reason and prerequisites
An attacker can exploit PPM-PFM to modify displayed application content without authorization. Specifically, the URL parameter NO_AUTH_CHECK appears to disable authorization checks, allowing malicious users to bypass authority checks by appending this parameter to URLs.
Additionally, CL_RPM_FILE_HTTP_HANDLER within PPM-PFM insufficiently encodes input parameters, leading to a reflected cross-site scripting (XSS) vulnerability. This vulnerability can be used to deface web content, steal user authentication information, and impersonate users, including administrators, thereby compromising application security.
An attacker exploiting this vulnerability can:
- Modify and deface displayed content.
- Steal authentication information from legitimate users.
- Impersonate users, potentially gaining full administrative access.
References
- 1731835 – Unauthorized modification of displayed content in PPM-PFM
- 1687722 – Unauthorized modification of displayed content in PPM
- 1668681 – Unauthorized modification of displayed content in PPM-PFM
Full note on SAP: SAP Support Launchpad note 1687863
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
