SAP Security Note
High priority
SAP security note 1686234, “Unauthorized modification of stored content in PA-PD-PM”, is a program error note released on May 8, 2012. Below are the symptom and SAP recommended solution.
Description
Symptom
The PA-PD-PM component is vulnerable to stored cross-site scripting (XSS) attacks. An attacker can exploit this vulnerability to:
- Modify application content without authorization.
- Persist the modified content.
- Potentially obtain authentication information from other legitimate users.
Exploiting this vulnerability can allow attackers to embed malicious content that is automatically rendered, steal user authentication data, and impersonate users to access sensitive information. If an administrator’s credentials are compromised, the security of the entire application may be at risk.
Solution
- Import the appropriate Support Package that corresponds to your SAP release.
- Implement the provided correction instructions detailed in the SAP Note.
References
This note refers to
Full note on SAP: SAP Support Launchpad note 1686234
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




