SAP security note 2658755, "[CVE-2018-2476] URL Redirection vulnerability in "Forums in SAP NetWeaver"". Below are the symptom and the SAP recommended solution.
Description
Symptom
Forums in SAP NetWeaver allows an attacker to redirect users to a malicious site due to insufficient URL validation.
Solution
The issue is resolved with the latest patch for Forums in SAP NetWeaver. Apply the latest patch to resolve the issue.
CVSS
Score 4.7/10 Vector: AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N
References
- CVE-2018-2476
Full note on SAP: SAP Support Launchpad note 2658755
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
