Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2020-6266 URL redirection in SAP Fiori for SAP S/4HANA, SAP security note 2911687

SAP Note 2911687

SAP security note 2911687, "[CVE-2020-6266] URL redirection in SAP Fiori for SAP S/4HANA". Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

SAP Fiori for SAP S/4HANA was previously susceptible to allowing users to be redirected to malicious sites due to insufficient URL validation.

  • Phishing Attacks: Attackers can craft malicious URLs to steal user credentials.
  • Malware Distribution: Users may be redirected to untrusted webpages containing malware or other malicious exploits.

Solution

URL and MIME type validations have been added in the backend to prevent unauthorized redirections.

Important: After implementing this note, ensure to apply Note 2911704 for a complete solution.

Reason and prerequisites

Proper URL and MIME type validation were not implemented, allowing for unauthorized URL redirection.

CVSS

Score 5.4 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

References

Affected components

  • S4CORE: Versions 101 to 104

Full note on SAP: SAP Support Launchpad note 2911687

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More