Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Potential false redirection of Web site content in SAP Internet Communication Framework, SAP security note 2193214

SAP Note 2193214

SAP security note 2193214, "Potential false redirection of Web site content in SAP Internet Communication Framework". Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

SAP Internet Communication Framework (ICF) is susceptible to phishing attacks that exploit URL redirection. An attacker can publish a URL that appears to originate from SAP ICF, which then redirects users to a malicious site of the attacker’s choice. This can deceive users into trusting the fake site and inadvertently disclose sensitive information, such as authentication credentials.

  • Malicious URLs redirecting users from legitimate SAP ICF pages to attacker-controlled websites.
  • Users may be tricked into entering sensitive information on fraudulent pages that mimic SAP ICF interfaces.

Solution

To mitigate this vulnerability, you should implement the support package mentioned in this SAP Note or apply the provided correction instructions.

References

Affected components

  • SAP_BASIS: Versions 700 to 750
  • SAP Internet Communication Framework (BC-MID-ICF)

Full note on SAP: SAP Support Launchpad note 2193214

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More