Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Potential false redirection of Web site content in BSP, SAP security note 1851123

SAP Note 1851123

SAP security note 1851123, "Potential false redirection of Web site content in BSP". Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

BSP IT00 can be exploited for phishing attacks by allowing attackers to publish a URL that appears to be from the legitimate product. This URL redirects victims to a malicious URL chosen by the attacker, enabling the attacker to gain the victim’s trust and elicit private data such as authentication information.

Solution

Please install the correction instructions attached to the note.

CVSS

Score 6.4 Vector: AV:N/AC:L/AU:N/C:P/I:P/A:N

Affected components

  • SAP_BASIS: Versions 700 to 702, 710 to 730, 731, 740

Full note on SAP: SAP Support Launchpad note 1851123

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More