Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized usage of application functionality in PLM-CFO, SAP security note 1515151

SAP Note 1515151

SAP security note 1515151, "Unauthorized usage of application functionality in PLM-CFO". Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

This security note has been updated. For more detailed information, see Security Notes 1567901 and 1572616.

Solution

Please apply the following steps:

  • Refer to Note 1520324 for additional information and instructions. The corrections from this note are a prerequisite for implementing this note.
  • Implement the correction instructions of this note. This will create the report BSP_XSRF_PARAM_CFOLDERS in your system.
  • Execute the report BSP_XSRF_PARAM_CFOLDERS and specify a corresponding transport request number when prompted. The report will populate the database table BSPTEMPXSRFSTORE with entries for the BSP applications adapted by this note.

Reason and prerequisites

PLM-CFO executes certain functions through referencing specific URLs. An attacker can trick an authenticated user’s browser into making a request containing a specific URL and parameters, causing the function to execute with the user’s rights. This can be exploited through Cross Site Scripting (XSS) or by presenting a clickable link to the victim.

References

Affected components

  • CPROJECTS: 310_620 to 310_640
  • CPRXRPM: 400, 450_700, 500_702

Full note on SAP: SAP Support Launchpad note 1515151

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More