SAP security note 1950292, "Potential false redirection of Web site content in SRM-EBP-CAT", is a note released on February 11, 2014. Below are the symptom and SAP recommended solution.
Description
Symptom
SRM-EBP-CAT can be exploited for phishing attacks by allowing an attacker to publish a URL that appears to be from the product, which redirects the victim to a malicious URL of the attacker’s choice. This enables the attacker to falsely gain the trust of the victim and obtain private data, such as authentication information.
Solution
Implement the provided correction instructions.
Reason and prerequisites
Certain pages within SRM-EBP-CAT allow cross-domain redirection. An attacker can embed a URL from a different domain into a URL of the target application and send it to a user. The user believes the content is from the legitimate application, but upon visiting the page, the content is served from the attacker’s chosen domain.
The attacker can then replicate pages of the legitimate application (e.g., a login page) to trick the victim into revealing sensitive information, such as passwords. Mitigation involves restricting redirections to relative or local domains only.
CVSS
Score 4.3 Vector: AV:N/AC:M/AU:N/C:P/I:N/A:N
Full note on SAP: SAP Support Launchpad note 1950292
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



