SAP security note 1898548, “Potential false redirection of Web site content in EA-HRGXX”. Below are the symptom and SAP recommended solution.
Description
Symptom
EA-HRGXX can be exploited for phishing attacks by allowing an attacker to publish a URL that appears to be from the product, which then redirects the victim to a URL chosen by the attacker. This enables the attacker to falsely gain the trust of the victim and elicit private data from them, such as authentication information.
Solution
Import the relevant support package.
Reason and prerequisites
Some pages within EA-HRGXX enable cross-domain redirection. An attacker can include a URL from a different domain in a URL of the target application, which can then be sent to a user of the target application. The user believes the content is from the target application, but the content is delivered from the attacker’s chosen domain. The attacker can mimic pages of the target application (e.g., a logon page) to deceive the victim into disclosing sensitive information like passwords. This can be mitigated by restricting redirections to relative or local domains only.
CVSS
Score 4.0 Vector: AV:N/AC:L/AU:S/C:P/I:N/A:N
Full note on SAP: SAP Support Launchpad note 1898548
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



