SAP Security Note
High priority
SAP security note 2198151, "Potential false redirection of web site content in Internet Communication of AS ABAP", is a program error note released on 08.12.2015. Below are the symptom, SAP recommended solution and CVSS assessment for this vulnerability.
Description
Symptom
Internet Communication of AS ABAP can be exploited for phishing attacks by allowing an attacker to publish a URL that appears to be from the product, which redirects victims to a malicious URL of the attacker's choosing. This enables attackers to gain victims' trust falsely and elicit private data such as authentication information.
Solution
Implement the patch level mentioned in this SAP Note. The correction in Internet Communication Manager prevents requests passed to the AS ABAP application from being constructed in a way that references attacker-chosen domains. Content references will remain within the intended AS ABAP system.
Reason and prerequisites
Some pages within Internet Communication of AS ABAP allow cross-domain redirection. An attacker can include a URL from a different domain in a target application's URL, which is then sent to a user. The user believes the content is from the target application, but it is actually delivered from the attacker's domain. This can be exploited to mimic pages of the target application (e.g., logon pages) to trick the victim into disclosing sensitive information like passwords.
CVSS
Score 5.8 Vector: AV:N/AC:M/PR:N/UI:N/S:U/C:P/I:P/A:N
Full note on SAP: SAP Support Launchpad note 2198151
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
