SAP security note 1613163, "Update #2 for XSS Vulnerability in PLM-CFO", is released on July 31, 2012. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
The original correction instructions provided in Security Note 1496707 for the XSS vulnerability were incorrect. This necessitates the release of Security Note 1613163 to provide accurate correction steps.
Solution
To resolve the XSS vulnerability, apply the updated correction instructions outlined in Security Note 1613163.
Reason and prerequisites
Implementation of Security Note 1496707 is required before applying Security Note 1613163.
References
- Security Note 1723907 – Update 1 to Security Note 1613163
- Security Note 1496707 – Unauthorized modification of displayed content in PLM-CFO
Affected components
- cFolder 5.0, applicable until SAPK-50006INCPRXRPM
Full note on SAP: SAP Support Launchpad note 1613163
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
