High priority
SAP security note 1946420, "Potential false redirection of Web site content in SRM-LA", is a note released on March 11, 2014. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
SRM-LA can be exploited for phishing attacks by allowing an attacker to publish a URL that appears to be from the product. This redirects the victim to a URL chosen by the attacker, enabling the attacker to gain the victim’s trust and elicit private data, such as authentication information.
Solution
Implement the latest LAC patch to resolve the issue:
- SAP LACWPS 6.0 "LAC05" (SP-Level #05, Patch-Level #15)
- SAP LACWPS 6.0 NW7.3: "LAC00" (SP-Level #00, Patch-Level #5)
CVSS
Score 5.0 Vector: AV:N/AC:L/AU:N/C:P/I:N/A:N
Affected components
- SRM_SERVER versions 550, 600, 700, 701, 702, 713
Full note on SAP: SAP Support Launchpad note 1946420
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
