SAP Security Note
High priority
SAP security note 2734580, “Information Disclosure in SAP ABAP Server”, is a note released on 14.07.2020. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
This note has been updated. We have added the note 2091403 as a prerequisite.
ABAP Server has a weakness in Internet Communication Framework’s logon procedure, which enables a malicious user to steal logon credentials of another user by providing a malicious URL.
Solution
- Harden the Logon Procedure: implement the support package mentioned in this SAP Note or the respective correction instructions.
- Implement Whitelist Protection: if the HTTP Whitelist Tool for Unified Connectivity (UCON) is available/active, activate the Trusted Network Zone for the scenario “HTTP Whitelist Scenario”. Otherwise, maintain the table HTTP_WHITELIST with entry type 21 to enable HTTP Whitelist Protection; for example, to allow a redirect to any relative path, leave all fields empty except Entry Type 21 and a proper Sort Key, e.g. 1000. This entry must be maintained for client 000.
Reason and prerequisites
A malicious user can manipulate certain parameters used in a URL. When the manipulated URL is presented to another user, selecting that URL might disclose the user’s credentials to the malicious user in another domain.
CVSS
Score 7.4 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N
References
This note refers to
Affected components
- SAP_BASIS 700 to 702
- SAP_BASIS 710 to 754+
Full note on SAP: SAP Support Launchpad note 2734580
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
