SAP security note 1694059, "Unauthorized Modification of Displayed Content in PLM-CFO", is a note released on May 8, 2012. Below are the symptom, SAP recommended solution and affected software components.
Description
Symptom
A reflected Cross Site Scripting (XSS) vulnerability has been identified in PLM-CFO. This issue allows malicious users to modify displayed application content without authorization and potentially steal authentication information from legitimate users. In cases where an administrator is impersonated, it could lead to a full compromise of the application's security.
Solution
Implement the program corrections detailed in the Correction Instructions tab of this SAP Security Note.
Reason and prerequisites
The vulnerability arises because pages within PLM-CFO do not sufficiently encode input and output parameters, resulting in the XSS issue.
Prerequisite notes:
Affected components
- CPROJECTS: Versions 310_620 to 310_640
- CPRXRPM: Versions 400, 450_700, and 500_702
Full note on SAP: SAP Support Launchpad note 1694059
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
