SAP security note 2193214, "Potential false redirection of Web site content in SAP Internet Communication Framework". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
SAP Internet Communication Framework (ICF) is susceptible to phishing attacks that exploit URL redirection. An attacker can publish a URL that appears to originate from SAP ICF, which then redirects users to a malicious site of the attacker’s choice. This can deceive users into trusting the fake site and inadvertently disclose sensitive information, such as authentication credentials.
- Malicious URLs redirecting users from legitimate SAP ICF pages to attacker-controlled websites.
- Users may be tricked into entering sensitive information on fraudulent pages that mimic SAP ICF interfaces.
Solution
To mitigate this vulnerability, you should implement the support package mentioned in this SAP Note or apply the provided correction instructions.
References
- SAP Note 1635860 – Blank URLs cause an exception in CHECK_HTTP_WHITELIST
- SAP Note 1768016 – Downport of parameters for CL_HTTP_UTILITY->IS_VALID_URL
- SAP Note 2091403 – Directory traversal in BC-MID-ICF
- SAP Note 2189853 – SAP Internet Communication Framework fails to validate HTTP_WHITELIST
Affected components
- SAP_BASIS: Versions 700 to 750
- SAP Internet Communication Framework (BC-MID-ICF)
Full note on SAP: SAP Support Launchpad note 2193214
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
