Medium priority
SAP security note 2973428, "Reverse Tabnabbing Vulnerability within SAP NetWeaver Application Server ABAP (Applications based on SAP GUI for HTML)", is a note released on February 9, 2021. Below are the symptom and SAP recommended solution.
Description
Symptom
Applications based on SAP GUI for HTML are vulnerable to Reverse Tabnabbing, allowing attackers to redirect users to malicious sites. This vulnerability can lead to:
- Phishing attacks
- Redirection to untrusted webpages containing malware or similar malicious exploits
Solution
To address this vulnerability, follow the steps below based on your system’s configuration:
- Update SAPEXE SAR Package: Determine the highest patch number of the SAPEXE SAR package for your kernel version on the SAP Support Portal. If the available SAPEXE patch number is greater than or equal to the patch level listed in the Support Packages & Patches section of this note for your SAP Kernel version, download and install the SAPEXE SAR package from the SAP Support Portal.
- Apply SAPWEBGUI.SAR Package: Applicable for systems running the latest 777, 773, 753, or 749 stack kernel. Apply the SAPWEBGUI.SAR package without updating the full SAP Kernel. Detailed instructions can be found in SAP Note 2412840.
- Update DW.SAR Archive: Applicable for systems not running the latest stack kernel or running with SAP Kernel 722. Download and install the most recent DW.SAR archive.
Reason and prerequisites
Usage of SAP GUI for HTML.
CVSS
Score 4.7 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N
References
- SAP Kernel 781 (2020) – Note 2959769
- SAP Kernel 777 (1909) – Note 2791294
- SAP Kernel 773 (1809) – Note 2649879
- SAP Kernel 753 (1709) – Note 2474329
- SAP Kernel 749 (1610) – Note 2375349
- SAP Kernel 722 – Note 2198998
- SAP Knowledge Base Article 3014875
Full note on SAP: SAP Support Launchpad note 2973428
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
