SAP security note 1851123, "Potential false redirection of Web site content in BSP". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
BSP IT00 can be exploited for phishing attacks by allowing attackers to publish a URL that appears to be from the legitimate product. This URL redirects victims to a malicious URL chosen by the attacker, enabling the attacker to gain the victim’s trust and elicit private data such as authentication information.
Solution
Please install the correction instructions attached to the note.
CVSS
Score 6.4 Vector: AV:N/AC:L/AU:N/C:P/I:P/A:N
Affected components
- SAP_BASIS: Versions 700 to 702, 710 to 730, 731, 740
Full note on SAP: SAP Support Launchpad note 1851123
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




