SAP security note 2197532, “Security vulnerabilities in an ICF service belonging to SAP ITS Mobile”. Below are the symptom and SAP recommended solution.
Description
Symptom
There is a possibility of Cross-Site Scripting (XSS) and URL redirection vulnerabilities in SAP ITS Mobile. The impacts of these vulnerabilities include:
- Phishing attacks: Attackers can steal user credentials or redirect users to malicious websites through URL redirection.
- Content defacement: Unauthorized modification of displayed content on a website via XSS.
- Session theft: Stealing authentication information related to a user’s current session through XSS.
Solution
To address these vulnerabilities, implement the Support Packages referenced by this SAP Note to delete the affected service. Deleting this service does not impact SAP ITS Mobile, as the service is intended solely for testing purposes.
As a temporary workaround, ensure that the service /default_host/sap/public/bc/its/mobile/rfid is deactivated (this is the default setting) via transaction SICF.
CVSS
Score 6.1 Vector: AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Full note on SAP: SAP Support Launchpad note 2197532
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
