Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Security vulnerabilities in an ICF service belonging to SAP ITS Mobile, SAP security note 2197532

SAP Note 2197532

SAP security note 2197532, “Security vulnerabilities in an ICF service belonging to SAP ITS Mobile”. Below are the symptom and SAP recommended solution.

Description

Symptom

There is a possibility of Cross-Site Scripting (XSS) and URL redirection vulnerabilities in SAP ITS Mobile. The impacts of these vulnerabilities include:

  • Phishing attacks: Attackers can steal user credentials or redirect users to malicious websites through URL redirection.
  • Content defacement: Unauthorized modification of displayed content on a website via XSS.
  • Session theft: Stealing authentication information related to a user’s current session through XSS.

Solution

To address these vulnerabilities, implement the Support Packages referenced by this SAP Note to delete the affected service. Deleting this service does not impact SAP ITS Mobile, as the service is intended solely for testing purposes.

As a temporary workaround, ensure that the service /default_host/sap/public/bc/its/mobile/rfid is deactivated (this is the default setting) via transaction SICF.

CVSS

Score 6.1 Vector: AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Full note on SAP: SAP Support Launchpad note 2197532

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More