SAP security note 2972275, "Reverse Tabnabbing vulnerability within SAP Business Server Pages Applications in SAP NetWeaver AS ABAP", is a note. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
UPDATE 9th of March 2021: This note has been re-released with updated ‘Correction Instructions’ information.
Applications based on SAP Business Server Pages allow an attacker to redirect users to a malicious site due to Reverse Tabnabbing vulnerabilities.
Some well-known impacts of Reverse Tabnabbing vulnerability are:
- Phishing attacks
- Redirect users to untrusted webpages containing malware or similar malicious exploits
Solution
By implementing this note, a default out-of-the-box protection is applied for all Business Server Pages applications.
SAP Knowledge Base Article 3014875 contains an overview of the corrections regarding Reverse Tabnabbing in SAP’s UI Frameworks.
Reason and prerequisites
This issue is not exploitable in cloud products hosted by SAP, but only in applications based on Business Server Pages in SAP NetWeaver AS ABAP on premise.
CVSS
Score 4.7 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N
References
Affected components
- SAP_BASIS 700 to 702
- SAP_BASIS 731
- SAP_BASIS 740
- SAP_BASIS 750 to 755
Full note on SAP: SAP Support Launchpad note 2972275
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
