Skip links

Potential false redirection of content in NWBC, SAP security note 1628709

Description

NWBC can  be  used  for  phishing  attacks  by  allowing  an  attacker to  publish  a URL  purporting  to  be  from  the  product,  which redirects  the  victim  to  a  URL  chosen  by  the attacker. This enables an attacker to falsely gain the trust of a victim and elicit private data from them (such as authentication information).

Available fix and Supported packages

  • BC-WD-CLT-BUS | 3.0 | 3.0
  • BC-WD-CLT-BUS | 3.5 | 3.5
  • NWBC NW BUSINESS CLIENT 3.0 | SP000 | 000010

Affected component

    BC-FES-BUS-RUN
    Runtime

CVSS

Score: 0

Exploit

Detailed vulnerability information added to RedRays Security Platform. Contact [email protected] for details.

URL

https://launchpad.support.sap.com/#/notes/1628709

TAGS

#Cross-domain-redirection
#NWBC
#NetWeaver-Business-Client

How to detect over 4100 vulnerabilities in SAP Systems?

More to explorer

Initiating SAP Penetration Testing

►   Pentest, short for penetration testing, refers to a set of processes that simulate an attacker’s actions to identify security vulnerabilities. Companies

SAP Security Patch Day RedRays

May 2024 SAP Security Patch Day

Vulnerability: Multiple vulnerabilities in SAP CX Commerce SAP Component: CEC-SCC-PLA-PL CVE ID: CVE-2019-17495 CVSS Score: 9.8 CVSS Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Category: Program error