SAP security note 1523140, "Unauthorized usage of application functionality in PPM-PRO", is a note. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
A malicious user can trigger functionality in PPM-PRO/cProjects without proper authentication and authorization. This results in unauthorized access to functionalities in PPM-PRO/cProjects and potential execution of functions with the rights of an authenticated user.
Solution
Implement the correction instructions provided in this note. This will also create the report BSP_XSRF_PARAM_CPROJECTS in your system. Note 1520324 must be implemented prior to this note.
Reason and prerequisites
PPM-PRO executes functions through specific URLs. An attacker can trick an authenticated user’s browser into making a malicious request containing specific URLs and parameters, leading to unauthorized actions.
References
Affected components
- PPM-PRO 300
- PPM-PRO 310_620 to 310_640
- PPM-PRO 400
Full note on SAP: SAP Support Launchpad note 1523140
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




