Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized usage of application functionality in PLM-CFO, SAP security note 1519001

SAP Note 1519001SAP Security NoteHigh priority

SAP security note 1519001, "Unauthorized usage of application functionality in PLM-CFO", is a program error note released on 14.12.2010. Below are the symptom and SAP recommended solution.

ComponentProduct Lifecycle Management > Collaboration Folders
CategoryProgram error
PriorityCorrection with high priority
TypeSAP Security Note
Version4
StatusReleased for Customer
Released on14.12.2010
LanguageEnglish

Description

Symptom

A malicious user can trigger functionality in PLM-CFO without authentication and authorization. When performing a mass download, the file is successfully downloaded, but an extra popup for an error appears.

Solution

Please implement the following correction instructions.

Reason and prerequisites

PLM-CFO executes certain functions by referencing specific URLs. An attacker can trick an authenticated user's browser into making a request with a specific URL and parameters, causing the function to execute with the user's privileges.

Potential attack vectors include:

  • Cross Site Scripting (XSS) to trigger the exploit.
  • Presenting a malicious link for the victim to click.

Full note on SAP: SAP Support Launchpad note 1519001

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More