SAP security note 1515151, "Unauthorized usage of application functionality in PLM-CFO". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
This security note has been updated. For more detailed information, see Security Notes 1567901 and 1572616.
Solution
Please apply the following steps:
- Refer to Note 1520324 for additional information and instructions. The corrections from this note are a prerequisite for implementing this note.
- Implement the correction instructions of this note. This will create the report
BSP_XSRF_PARAM_CFOLDERSin your system. - Execute the report
BSP_XSRF_PARAM_CFOLDERSand specify a corresponding transport request number when prompted. The report will populate the database tableBSPTEMPXSRFSTOREwith entries for the BSP applications adapted by this note.
Reason and prerequisites
PLM-CFO executes certain functions through referencing specific URLs. An attacker can trick an authenticated user’s browser into making a request containing a specific URL and parameters, causing the function to execute with the user’s rights. This can be exploited through Cross Site Scripting (XSS) or by presenting a clickable link to the victim.
References
- 1699886 – Dump occurs while starting cFolder from notification mail
- 1674620 – Error while executing report BSP_XSRF_PARAM_CFOLDERS
- 1666244 – cFolders: Composite SAP Note – Security
- 1660140 – Error occurs while exporting BOM to cFolder using CFE02
- 1599647 – Application generates short dump
- 1572616 – Update #2 to Security Note 1515151
- 1567901 – Update #1 to Security Note 1515151
- 1560533 – System message page generates short dump
- 1555062 – Unauthorized usage of application functionality in PLM-CFO
- 1543703 – Redlining is not working
- 1540729 – ASU content for activating XSRF protection for BSP
- 1538581 – Not able to navigate from SRM to cFolder
Affected components
- CPROJECTS: 310_620 to 310_640
- CPRXRPM: 400, 450_700, 500_702
Full note on SAP: SAP Support Launchpad note 1515151
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
