Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

URL Redirection Vulnerability in SAP NetWeaver Logon Application, SAP security note 2423540

SAP Note 2423540

SAP security note 2423540, “URL Redirection Vulnerability in SAP NetWeaver Logon Application”. Below are the symptom and SAP recommended solution.

Description

Symptom

Updated on 29th March: This note has been updated. The fix has been down ported to the following SPs. Please refer to note 2524134 for more details.

  • J2EE ENGINE APPLICATIONS 7.31: SP017 & SP018
  • J2EE ENGINE APPLICATIONS 7.40: SP012 & SP013

The Logon Application of AS Java allows an attacker to redirect users to a malicious site due to insufficient URL validation.

Impacts of the URL Redirection Vulnerability:

  • Phishing attacks to steal credentials of the victim.
  • Redirecting users to untrusted webpages that contain malware or similar malicious exploits.

Solution

Apply the latest patches relevant to your version of AS Java according to the “SP Patch Level” section of this note.

With the described fix, the URL is validated against some special characters, which are removed from the URL if necessary.

Reason and prerequisites

Insufficient URL validation in the Logon Application of AS Java.

CVSS

Score 4.3 Vector: AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

References

Full note on SAP: SAP Support Launchpad note 2423540

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More