SAP Security Note
SAP security note 887322, “Whitelist checks of sap-exit URL”, is released on 08.10.2009. Below are the symptom and SAP recommended solution.
Description
Symptom
The BSP runtime supports a URL parameter sap-exiturl, which can be used to redirect to another site after the application has completed. This is particularly useful when using a foreign portal or when called from other applications, allowing the browser to return to a known destination after the application ends.
However, it is also possible to craft a link that causes the application to navigate to an unintended site after completion. Until now, there have been no checks on this URL, and it was not possible to configure constraints on the types of URLs that are accepted.
Solution
The BSP runtime has been updated to implement a whitelist check on sap-exiturl. Refer to Note 853878 for details on how the whitelist operates and how to configure it. For sap-exiturl, the type is set to ’02’.
However, the whitelist enhancements introduced in Note 853878 are only available in the latest service packs. Therefore, it is not possible to apply this correction across all service packs using this approach.
Currently, it is perceived that sap-exiturl is not widely used. Given that this is a security-relevant issue, correction instructions have been created to remove the sap-exiturl functionality in lower service packs. IMPORTANT: In lower service packs, the functionality is deleted. If you rely on this functionality and are using only in-house systems, you may choose not to apply this note and continue using sap-exiturl as is. If this functionality is required with additional whitelist checks, please open an OSS message, queue BC-BSP, and request that the problem ticket be routed immediately to development. We will then explore possible solutions, including local code modifications based on your requirements.
Changes per Release/SP:
- 610: Deleted SP45, deleted Notes SP01-44
- 620: Fixed SP56, deleted Notes SP<54, added whitelist check for Notes SP54-55
- 640: Fixed SP15, deleted Notes SP<14, added whitelist check for Notes SP14
- 700: Fixed SP06, added whitelist check for Notes SP03-05
References
This note refers to
Full note on SAP: SAP Support Launchpad note 887322
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




