Low priority
SAP security note 2394536, "URL Redirection Vulnerability in SAP NetWeaver K.M. Web Page Composer", is a program error note released on August 8, 2017. Below are the symptom and SAP recommended solution.
Description
Symptom
Knowledge Management and Collaboration and Web Page Composer allows an attacker to redirect users to a malicious site due to insufficient URL validation.
Impacts of URL Redirection Vulnerability:
- Phishing attacks to steal credentials of the victim
- Redirect users to untrusted webpages containing malware or similar malicious exploits
Solution
The fix is provided in patches for KMC-CM and KMC-WPC components.
The portal has to be restarted after deploying the patches, and all XMLForms projects have to be regenerated. For more information on how to regenerate XMLForms, check the note 2342421 – How to Regenerate XML Form Projects.
CVSS
Score 3.5 Vector: AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N
Full note on SAP: SAP Support Launchpad note 2394536
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
