Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Reverse Tabnabbing vulnerability within SAP CRM WebClient UI, SAP security note 2994289

SAP Note 2994289

SAP security note 2994289, "Reverse Tabnabbing vulnerability within SAP CRM WebClient UI", is a note. Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

Applications based on SAP CRM WebClient UI allow an attacker to redirect users to a malicious site due to Reverse Tabnabbing vulnerabilities. This can lead to:

  • Phishing attacks to steal user credentials.
  • Redirection to untrusted webpages containing malware or other malicious exploits.

Solution

Implement the attached Correction Instructions or apply the relevant Support Package for your software component version.

WarningThese manual steps must be performed manually and separately in each system before importing the Note.

CVSS

Score 4.1 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:L/A:N

References

Affected components

  • S4FND 102, 103, 104, 105
  • WEBCUIF 700, 701, 730, 731, 746, 747, 748, 800, 801

Full note on SAP: SAP Support Launchpad note 2994289

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More