Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Possible incorrect redirection of web site content in ICF, SAP security note 1641103

SAP Note 1641103
High priority

SAP security note 1641103, "Possible incorrect redirection of web site content in ICF", was released on February 14, 2012. Below are the symptom and SAP recommended solution.

ComponentBasis Components > Middleware > Internet Communication Framework
PriorityCorrection with high priority
Released onFebruary 14, 2012

Description

Symptom

The Internet Communication Framework (ICF) can be exploited for phishing attacks. An attacker can publish a URL that appears to be from a legitimate product. When a victim visits this URL, they are redirected to a malicious URL chosen by the attacker. This can deceive the victim into trusting the site and disclosing private information, such as authentication credentials.

Solution

Implement the source code changes as outlined in the correction instructions or import the relevant Support Package provided by SAP. For more details, visit the SAP Support Portal.

Full note on SAP: SAP Support Launchpad note 1641103

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More