Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Potential false redirection of Web site content in EPM, SAP security note 1833139

SAP Note 1833139
SAP Security Note
Medium priority

SAP security note 1833139, "Potential false redirection of Web site content in EPM", is a program error note released on 14.05.2013. Below are the symptom and SAP recommended solution.

ComponentBusiness intelligence solutions > Business intelligence platform > BI Workspaces (Dashboard Builder)
CategoryProgram error
PriorityCorrection with medium priority
TypeSAP Security Note
Version3
StatusReleased for Customer
Released on14.05.2013
LanguageEnglish

Description

Symptom

XI3.1 Performance Management can be used for phishing attacks by allowing an attacker to publish a URL purporting to be from the product, which redirects the victim to a URL chosen by the attacker. This enables an attacker to falsely gain the trust of a victim and elicit private data from them (such as authentication information).

Solution

Issue is resolved in the following Support Packages:

  • XI3.1 SP5 FP5
  • XI3.1 SP6 FP1
  • XI3.1 SP7 onward

It is not relevant for BI4.0.

Reason and prerequisites

Some pages within Performance Management enable a cross-domain redirection to occur. An attacker can include a URL from a different domain in a URL of the target application, which can then be sent to a user of the target application. The user thinks that the content is from the target application, but when they visit such a page, the content is delivered from the domain chosen by the attacker. The attacker can then mimic pages of the target application (for example, a logon page) to get the victim to disclose information they would not otherwise reveal to the attacker (such as their password).

Mitigation: Restrict redirections to relative or local domains only.

CVSS

Score 4.3 Vector: AV:N/AC:M/AU:N/C:N/I:P/A:N

Full note on SAP: SAP Support Launchpad note 1833139

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More