Medium priority
SAP security note 2081029, "Potentially false redirection of Web site content in Web Dynpro ABAP application", is a note released on 17.04.2018. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Web Dynpro ABAP can be exploited for phishing attacks by allowing attackers to publish URLs that redirect victims to malicious sites. This redirection enables attackers to mimic trusted pages and elicit private data, such as authentication information.
Solution
Implement the source code changes as per the correction instructions provided in the note or import the relevant Support Package. After applying the correction, ensure that entries are maintained in the HTTP_WHITELIST table for ENTRY_TYPE 10 and 11.
References
Referenced by
Affected components
- SAP_BASIS (700 to 731)
- SAP_UI 740
Full note on SAP: SAP Support Launchpad note 2081029
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
