SAP security note 2974582, "[CVE-2021-21478] Reverse Tabnabbing vulnerability in SAP NetWeaver Application Server ABAP (Applications based on Web Dynpro ABAP)", is a note. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Applications based on SAP Web Dynpro ABAP allow an attacker to redirect users to a malicious site due to Reverse Tabnabbing vulnerabilities.
Impacts of the Reverse Tabnabbing Vulnerability:
- Phishing attacks
- Redirecting users to untrusted webpages containing malware or similar malicious exploits.
Solution
Implementing this security note applies a default out-of-the-box protection for all Web Dynpro ABAP applications. For more granular, application-specific control, refer to SAP Note 2984977.
Mandatory Precondition: Ensure that you have implemented the latest Unified Rendering release as per SAP Note 2090746.
SAP Knowledge Base Article: refer to SAP Note 3014875 for an overview of corrections regarding Reverse Tabnabbing in SAP’s UI Frameworks.
Reason and prerequisites
The vulnerability exists because the Web Dynpro ABAP Framework is used in the affected applications.
CVSS
Score 4.7 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N
References
- SAP Note 3014875: Reverse Tabnabbing attack in SAP Netweaver AS ABAP and SAP UI5 applications on multiple platforms.
- SAP Note 2984977: Web Dynpro ABAP – Opener Browsing Context Application Parameter.
- SAP Note 2090746: WD ABAP: Unified Rendering Update with TCI – Instructions and Related SAP Notes.
Affected components
- SAP_UI 750 to 755
- SAP_BASIS 700 to 804
Full note on SAP: SAP Support Launchpad note 2974582
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
