Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Potential false redirection of web site content in Internet Communication of AS ABAP, SAP security note 2198151

SAP Note 2198151
SAP Security Note
High priority

SAP security note 2198151, "Potential false redirection of web site content in Internet Communication of AS ABAP", is a program error note released on 08.12.2015. Below are the symptom, SAP recommended solution and CVSS assessment for this vulnerability.

CategoryProgram error
PriorityHigh priority
TypeSAP Security Note
Version2
StatusReleased for Customer
Released on08.12.2015
LanguageEnglish

Description

Symptom

Internet Communication of AS ABAP can be exploited for phishing attacks by allowing an attacker to publish a URL that appears to be from the product, which redirects victims to a malicious URL of the attacker's choosing. This enables attackers to gain victims' trust falsely and elicit private data such as authentication information.

Solution

Implement the patch level mentioned in this SAP Note. The correction in Internet Communication Manager prevents requests passed to the AS ABAP application from being constructed in a way that references attacker-chosen domains. Content references will remain within the intended AS ABAP system.

Reason and prerequisites

Some pages within Internet Communication of AS ABAP allow cross-domain redirection. An attacker can include a URL from a different domain in a target application's URL, which is then sent to a user. The user believes the content is from the target application, but it is actually delivered from the attacker's domain. This can be exploited to mimic pages of the target application (e.g., logon pages) to trick the victim into disclosing sensitive information like passwords.

CVSS

Score 5.8 Vector: AV:N/AC:M/PR:N/UI:N/S:U/C:P/I:P/A:N

Full note on SAP: SAP Support Launchpad note 2198151

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More