SAP security note 2423540, “URL Redirection Vulnerability in SAP NetWeaver Logon Application”. Below are the symptom and SAP recommended solution.
Description
Symptom
Updated on 29th March: This note has been updated. The fix has been down ported to the following SPs. Please refer to note 2524134 for more details.
- J2EE ENGINE APPLICATIONS 7.31: SP017 & SP018
- J2EE ENGINE APPLICATIONS 7.40: SP012 & SP013
The Logon Application of AS Java allows an attacker to redirect users to a malicious site due to insufficient URL validation.
Impacts of the URL Redirection Vulnerability:
- Phishing attacks to steal credentials of the victim.
- Redirecting users to untrusted webpages that contain malware or similar malicious exploits.
Solution
Apply the latest patches relevant to your version of AS Java according to the “SP Patch Level” section of this note.
With the described fix, the URL is validated against some special characters, which are removed from the URL if necessary.
Reason and prerequisites
Insufficient URL validation in the Logon Application of AS Java.
CVSS
Score 4.3 Vector: AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
References
Full note on SAP: SAP Support Launchpad note 2423540
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
