Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized change of displayed contents in CO-PC-PCP-REF, SAP security note 1655180

SAP Note 1655180
SAP Security Note
High priority

SAP security note 1655180, "Unauthorized change of displayed contents in CO-PC-PCP-REF", is a note released on January 10, 2012. Below are the symptom and SAP recommended solution.

ComponentControlling > Product Cost Controlling > Product Cost Planning > Reference and Simulation Costing
PriorityCorrection with high priority
TypeSAP Security Note
StatusReleased for Customer
Released onJanuary 10, 2012

Description

Symptom

An attacker can exploit CO-PC-PCP-REF to modify displayed application content without authorization and potentially obtain authentication information from other legitimate users.

Solution

Implement the attached program correction to mitigate the vulnerability.

Reason and prerequisites

Pages within CO-PC-PCP-REF do not sufficiently encode input parameters, resulting in a reflected XSS vulnerability. This flaw allows attackers to deface web content or steal user authentication information, which can lead to user impersonation and full compromise of application security.

Full note on SAP: SAP Support Launchpad note 1655180

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More