SAP security note 2994289, "Reverse Tabnabbing vulnerability within SAP CRM WebClient UI", is a note. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Applications based on SAP CRM WebClient UI allow an attacker to redirect users to a malicious site due to Reverse Tabnabbing vulnerabilities. This can lead to:
- Phishing attacks to steal user credentials.
- Redirection to untrusted webpages containing malware or other malicious exploits.
Solution
Implement the attached Correction Instructions or apply the relevant Support Package for your software component version.
CVSS
Score 4.1 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:L/A:N
References
- 3040219 – BSP error in WUI / SolMan
- 3014875 – Reverse Tabnabbing attack in SAP Netweaver AS ABAP and SAP UI5 applications on multiple platforms
Affected components
- S4FND 102, 103, 104, 105
- WEBCUIF 700, 701, 730, 731, 746, 747, 748, 800, 801
Full note on SAP: SAP Support Launchpad note 2994289
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
