Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

URL Redirection vulnerability in SAP NetWeaver K.M. Web Page Composer, SAP security note 2394536

SAP Note 2394536
Low priority

SAP security note 2394536, "URL Redirection Vulnerability in SAP NetWeaver K.M. Web Page Composer", is a program error note released on August 8, 2017. Below are the symptom and SAP recommended solution.

CategoryProgram error
PriorityLow priority
Released onAugust 8, 2017

Description

Symptom

Knowledge Management and Collaboration and Web Page Composer allows an attacker to redirect users to a malicious site due to insufficient URL validation.

Impacts of URL Redirection Vulnerability:

  • Phishing attacks to steal credentials of the victim
  • Redirect users to untrusted webpages containing malware or similar malicious exploits

Solution

The fix is provided in patches for KMC-CM and KMC-WPC components.

The portal has to be restarted after deploying the patches, and all XMLForms projects have to be regenerated. For more information on how to regenerate XMLForms, check the note 2342421 – How to Regenerate XML Form Projects.

CVSS

Score 3.5 Vector: AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N

Full note on SAP: SAP Support Launchpad note 2394536

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More