Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Update 1 to 2423540 URL Redirection Vulnerability in SAP NetWeaver Logon Application, SAP security note 2524134

SAP Note 2524134SAP Security NoteMedium priority

SAP security note 2524134, “Update 1 to 2423540: URL Redirection Vulnerability in SAP NetWeaver Logon Application”, is a program error note released on 29.08.2017. Below are the symptom and SAP recommended solution.

ComponentBasis Components > NetWeaver Application Server Java > Security, User Management
CategoryProgram error
PriorityCorrection with medium priority
TypeSAP Security Note
Version2
StatusReleased for Customer
Released on29.08.2017
LanguageEnglish

Description

Symptom

This SAP Note supplements the corrections provided in security note 2423540. Additional corrections are provided in the following Support Package patch levels:

  • J2EE ENGINE APPLICATIONS 7.31: SP017, SP018
  • J2EE ENGINE APPLICATIONS 7.40: SP012, SP013

Solution

Apply the latest patches relevant to your version of AS Java according to the “SP Patch Level” section of this note.

With the described fix, the URL is validated against special characters, which are removed from the URL if necessary.

Reason and prerequisites

The fix described in Note 2423540 has been down ported to the mentioned Support Package levels.

References

Full note on SAP: SAP Support Launchpad note 2524134

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More