Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2020-6266 URL redirection in SAP Fiori for SAP S/4HANA, SAP security note 2911704

SAP Note 2911704

SAP security note 2911704, "[CVE-2020-6266] URL redirection in SAP Fiori for SAP S/4HANA". Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

SAP Fiori for SAP S/4HANA was previously vulnerable to URL redirection attacks due to insufficient URL validation. This vulnerability allows attackers to redirect users to malicious sites, leading to potential phishing attacks to steal credentials or redirecting users to untrusted webpages containing malware.

  • Phishing Attacks: Attackers can deceive users into providing their credentials.
  • Malware Distribution: Users can be redirected to sites hosting malicious software or exploits.

Solution

URL and MIME type validations have been enhanced in the frontend to prevent unauthorized redirections.

Prerequisite: Before implementing this note, ensure that Note 2911687 containing the necessary backend code changes is applied.

Reason and prerequisites

The vulnerability arises from inadequate validation of URL and MIME type patterns in the frontend.

CVSS

Score 5.4 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

References

Affected components

  • UIS4HOP1: Versions 200 to 500+

Full note on SAP: SAP Support Launchpad note 2911704

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More