SAP security note 2524134, “Update 1 to 2423540: URL Redirection Vulnerability in SAP NetWeaver Logon Application”, is a program error note released on 29.08.2017. Below are the symptom and SAP recommended solution.
Description
Symptom
This SAP Note supplements the corrections provided in security note 2423540. Additional corrections are provided in the following Support Package patch levels:
- J2EE ENGINE APPLICATIONS 7.31: SP017, SP018
- J2EE ENGINE APPLICATIONS 7.40: SP012, SP013
Solution
Apply the latest patches relevant to your version of AS Java according to the “SP Patch Level” section of this note.
With the described fix, the URL is validated against special characters, which are removed from the URL if necessary.
Reason and prerequisites
The fix described in Note 2423540 has been down ported to the mentioned Support Package levels.
References
Full note on SAP: SAP Support Launchpad note 2524134
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
