Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2020-6365 Reverse Tabnabbing vulnerability in SAP NetWeaver AS Java Start Page, SAP security note 2965315

SAP Note 2965315SAP Security NoteMedium priority

SAP security note 2965315, "[CVE-2020-6365] Reverse Tabnabbing vulnerability in SAP NetWeaver AS Java Start Page", is a program error note released on October 13, 2020. Below are the symptom, SAP recommended solution and the affected software components.

CategoryProgram error
PriorityCorrection with medium priority
TypeSAP Security Note
StatusReleased for Customer
Released onOctober 13, 2020

Description

Symptom

SAP Security Note 2965315 addresses a reverse tabnabbing vulnerability in the SAP NetWeaver Application Server (AS) Java Start Page. This vulnerability allows an unauthenticated remote attacker to redirect users to a malicious site due to insufficient URL validation. This can facilitate phishing attacks to steal user credentials or redirect users to untrusted web pages containing malware.

Solution

To mitigate this vulnerability, update your SAP NetWeaver AS Java to a release or Support Package (SP) where the issue is resolved. Refer to the "Validity" and "Support Packages & Patches" sections of SAP Note 2965315 for detailed instructions and available patches.

CVSS

Score 4.7 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N

References

Affected components

  • SAP NetWeaver AS Java versions 7.10 to 7.50

Full note on SAP: SAP Support Launchpad note 2965315

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More