SAP security note 1593294, “Update #1 to Security Note 1496707”. Below are the symptom and SAP recommended solution.
Description
Symptom
Correction instructions provided for the vulnerability XSS addressed in Security Note 1496707 must be corrected for the following releases:
- cFolder 5.0: till SAPK-50005INCPRXRPM
Solution
Please apply the correction instruction to resolve the issue. For releases cFolders 3.1, 4.0, and 4.5, implement Note 1555371.
Reason and prerequisites
Security Notes 1496707 contains correction instructions which are erroneous. The implementation of Security Notes 1496707 is a prerequisite for applying this note.
References
- 1666244: cFolders: Composite SAP Note – Security
- 1555371: Update #1 to Security Note 1466863
- 1543703: Redlining is not working
- 1496707: Unauthorized modification of displayed content in PLM-CFO
- 1466863: Unauthorized modification of displayed content in PLM-CFO
Full note on SAP: SAP Support Launchpad note 1593294
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
