Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Potentially false redirection of Web site content in Web Dynpro ABAP application, SAP security note 2081029

SAP Note 2081029
Medium priority

SAP security note 2081029, "Potentially false redirection of Web site content in Web Dynpro ABAP application", is a note released on 17.04.2018. Below are the symptom, SAP recommended solution and the affected software components.

PriorityCorrection with medium priority
StatusReleased for Customer
Released on17.04.2018

Description

Symptom

Web Dynpro ABAP can be exploited for phishing attacks by allowing attackers to publish URLs that redirect victims to malicious sites. This redirection enables attackers to mimic trusted pages and elicit private data, such as authentication information.

Solution

Implement the source code changes as per the correction instructions provided in the note or import the relevant Support Package. After applying the correction, ensure that entries are maintained in the HTTP_WHITELIST table for ENTRY_TYPE 10 and 11.

References

Referenced by

Affected components

  • SAP_BASIS (700 to 731)
  • SAP_UI 740

Full note on SAP: SAP Support Launchpad note 2081029

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More