Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Potential false redirection of Web site content in EA-HRGXX, SAP security note 1898548

SAP Note 1898548

SAP security note 1898548, “Potential false redirection of Web site content in EA-HRGXX”. Below are the symptom and SAP recommended solution.

Description

Symptom

EA-HRGXX can be exploited for phishing attacks by allowing an attacker to publish a URL that appears to be from the product, which then redirects the victim to a URL chosen by the attacker. This enables the attacker to falsely gain the trust of the victim and elicit private data from them, such as authentication information.

Solution

Import the relevant support package.

Reason and prerequisites

Some pages within EA-HRGXX enable cross-domain redirection. An attacker can include a URL from a different domain in a URL of the target application, which can then be sent to a user of the target application. The user believes the content is from the target application, but the content is delivered from the attacker’s chosen domain. The attacker can mimic pages of the target application (e.g., a logon page) to deceive the victim into disclosing sensitive information like passwords. This can be mitigated by restricting redirections to relative or local domains only.

CVSS

Score 4.0 Vector: AV:N/AC:L/AU:S/C:P/I:N/A:N

Full note on SAP: SAP Support Launchpad note 1898548

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More