High priority
SAP security note 1661838, "Unauthorized modification of stored content in CA-GTF-PCF", is a program error note released on 25.02.2014. Below are the symptom and SAP recommended solution.
Description
Symptom
CA-GTF-PCF can be exploited by an attacker to modify application content without authorization. This vulnerability allows the persistence of modified content and the potential theft of authentication information from legitimate users.
This vulnerability allows:
- Content Modification: Permanently alter displayed content on a website without targeting individual users.
- Authentication Theft: Steal users’ authentication information, enabling impersonation.
- Security Compromise: If an administrator is impersonated, the entire application’s security may be compromised.
Solution
Implement the relevant support package or follow the correction instructions provided in the note.
Full note on SAP: SAP Support Launchpad note 1661838
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
