Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Update #1 to Security Note 1466863, SAP security note 1555371

SAP Note 1555371
SAP Security Note
High priority

SAP security note 1555371, “Update #1 to Security Note 1466863”, is released on 06.03.2012. Below are the symptom and SAP recommended solution.

ComponentProduct Lifecycle Management > Collaboration Folders (PLM-CFO)
PriorityCorrection with high priority
TypeSAP Security Note
Version6
StatusReleased for Customer
Released on06.03.2012

Description

Symptom

Correction instructions provided for the vulnerability XSS addressed in Security Note 1466863 must be corrected for the following releases:

  • cFolder 4.5: till SAPK-45010INCPRXRPM
  • cFolder 4.0: till SAPK-40019INCPRXRPM
  • cFolder 3.1: till SAPK-31219INCPROJECT

Solution

Please apply the correction instruction to resolve the issue.

For release cFolders 5.0, note 1593294 has to be implemented.

Reason and prerequisites

Security Notes 1466863 contains correction instructions which are erroneous. The implementation of Security Notes 1466863 is a prerequisite for applying this note.

References

Full note on SAP: SAP Support Launchpad note 1555371

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More