SAP security note 2965315, "[CVE-2020-6365] Reverse Tabnabbing vulnerability in SAP NetWeaver AS Java Start Page", is a program error note released on October 13, 2020. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
SAP Security Note 2965315 addresses a reverse tabnabbing vulnerability in the SAP NetWeaver Application Server (AS) Java Start Page. This vulnerability allows an unauthenticated remote attacker to redirect users to a malicious site due to insufficient URL validation. This can facilitate phishing attacks to steal user credentials or redirect users to untrusted web pages containing malware.
Solution
To mitigate this vulnerability, update your SAP NetWeaver AS Java to a release or Support Package (SP) where the issue is resolved. Refer to the "Validity" and "Support Packages & Patches" sections of SAP Note 2965315 for detailed instructions and available patches.
CVSS
Score 4.7 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N
References
Affected components
- SAP NetWeaver AS Java versions 7.10 to 7.50
Full note on SAP: SAP Support Launchpad note 2965315
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
