Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Reverse Tabnabbing vulnerability within SAP NetWeaver Application Server ABAP (Applications based on SAP GUI for HTML), SAP security note 2973428

SAP Note 2973428
Medium priority

SAP security note 2973428, "Reverse Tabnabbing Vulnerability within SAP NetWeaver Application Server ABAP (Applications based on SAP GUI for HTML)", is a note released on February 9, 2021. Below are the symptom and SAP recommended solution.

ComponentBasis Components > Frontend Services > SAP Internet Transaction Server
PriorityCorrection with medium priority
StatusReleased for Customer
Released onFebruary 9, 2021

Description

Symptom

Applications based on SAP GUI for HTML are vulnerable to Reverse Tabnabbing, allowing attackers to redirect users to malicious sites. This vulnerability can lead to:

  • Phishing attacks
  • Redirection to untrusted webpages containing malware or similar malicious exploits

Solution

To address this vulnerability, follow the steps below based on your system’s configuration:

  • Update SAPEXE SAR Package: Determine the highest patch number of the SAPEXE SAR package for your kernel version on the SAP Support Portal. If the available SAPEXE patch number is greater than or equal to the patch level listed in the Support Packages & Patches section of this note for your SAP Kernel version, download and install the SAPEXE SAR package from the SAP Support Portal.
  • Apply SAPWEBGUI.SAR Package: Applicable for systems running the latest 777, 773, 753, or 749 stack kernel. Apply the SAPWEBGUI.SAR package without updating the full SAP Kernel. Detailed instructions can be found in SAP Note 2412840.
  • Update DW.SAR Archive: Applicable for systems not running the latest stack kernel or running with SAP Kernel 722. Download and install the most recent DW.SAR archive.

Reason and prerequisites

Usage of SAP GUI for HTML.

CVSS

Score 4.7 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N

References

Full note on SAP: SAP Support Launchpad note 2973428

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More