Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized modification of displayed content in PLM-CFO., SAP security note 1466863

SAP Note 1466863
SAP Security Note
High priority

SAP security note 1466863, "Unauthorized modification of displayed content in PLM-CFO.", is a program error note released on July 31, 2012. Below are the symptom, SAP recommended solution and the affected software components.

ComponentProduct Lifecycle Management > Collaboration Folders (PLM-CFO)
PriorityCorrection with High Priority
TypeSAP Security Note
Version6
StatusReleased for Customer
Released onJuly 31, 2012
LanguageEnglish

Description

Symptom

This security note addresses a reflected Cross Site Scripting (XSS) vulnerability in the Product Lifecycle Management – Collaboration Folders (PLM-CFO) component. A malicious user could exploit this vulnerability to modify displayed application content without authorization and potentially steal authentication information from other users.

Solution

Apply the correction instructions provided in this security note to resolve the XSS vulnerability.

References

Affected components

  • CPROJECTS, versions 310_620 to 310_640
  • CPRXRPM, versions 400, 450_700, 500_702

Full note on SAP: SAP Support Launchpad note 1466863

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More