SAP security note 1718922, "Potential false redirection in workflow modeler portal", addresses the following vulnerability. Below are the symptom, reason and SAP recommended solution for this note.
Description
Symptom
The Workflow Modeler Portal can be used for phishing attacks by allowing an attacker to publish a URL purporting to be from the product, which redirects the victim to a URL chosen by the attacker. This enables an attacker to falsely gain the trust of a victim and elicit private data from them (such as authentication information).
Solution
The Workflow Modeler Portal is obsolete and needs to be deactivated. The deactivation is delivered in the following service packs:
- SAP_BASIS 730 SAPKB73008
- SAP_BASIS 720 SAPKB72008
- SAP_BASIS 711 SAPKB71110
- SAP_BASIS 710 SAPKB71015
- SAP_BASIS 702 SAPKB70212
- SAP_BASIS 701 SAPKB70112
- SAP_BASIS 700 SAPKB70027
- SAP_BASIS 640 SAPKB64030
Reason and prerequisites
Some pages within the Workflow Modeler Portal enable a cross-domain redirection to occur. An attacker can include a URL from a different domain in a URL of the target application, which can then be sent to a user of the target application. The user thinks that the content is from the target application, but when they visit such a page, the content is delivered from the domain chosen by the attacker. The attacker can then mimic pages of the target application (for example, a logon page) to get the victim to disclose information they would not otherwise reveal to the attacker (such as their password). This can be mitigated by restricting redirections to relative or local domains only.
Full note on SAP: SAP Support Launchpad note 1718922
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
