Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Potential false redirection of Web site content in SRM-EBP-CAT, SAP security note 1950292

SAP Note 1950292High priority

SAP security note 1950292, "Potential false redirection of Web site content in SRM-EBP-CAT", is a note released on February 11, 2014. Below are the symptom and SAP recommended solution.

ComponentSupplier Relationship Management > SRM > Catalog Interface
PriorityHigh priority
StatusReleased for Customer
Released onFebruary 11, 2014

Description

Symptom

SRM-EBP-CAT can be exploited for phishing attacks by allowing an attacker to publish a URL that appears to be from the product, which redirects the victim to a malicious URL of the attacker’s choice. This enables the attacker to falsely gain the trust of the victim and obtain private data, such as authentication information.

Solution

Implement the provided correction instructions.

Reason and prerequisites

Certain pages within SRM-EBP-CAT allow cross-domain redirection. An attacker can embed a URL from a different domain into a URL of the target application and send it to a user. The user believes the content is from the legitimate application, but upon visiting the page, the content is served from the attacker’s chosen domain.

The attacker can then replicate pages of the legitimate application (e.g., a login page) to trick the victim into revealing sensitive information, such as passwords. Mitigation involves restricting redirections to relative or local domains only.

CVSS

Score 4.3 Vector: AV:N/AC:M/AU:N/C:P/I:N/A:N

Full note on SAP: SAP Support Launchpad note 1950292

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More