SAP Security Note
Medium priority
SAP security note 2520995, "[CVE-2017-16679] URL Redirection vulnerability in Startup Service", is a program error note released on 12.12.2017. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Startup Service allows an attacker to redirect users to a malicious site due to insufficient URL validation.
Some well-known impacts of URL Redirection vulnerability are:
- Phishing attacks to steal credentials of the victim
- Redirect users to untrusted webpages containing malware or similar malicious exploits
Solution
With this fix, the Startup Service does not use information from the request to generate the redirect response. It is no longer possible for an attacker to influence the redirect response.
Action Required: Use Startup Service and hostagent with the patch level specified in this SAP Note or a higher patch level.
Reason and prerequisites
An attacker could influence the content of a redirect response and redirect users to untrusted webpages.
CVSS
Score 5.3 / 10 Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Affected components
- KRNL64UC: 7.21, 7.21EXT, 7.22, 7.22EXT, 7.49, 7.53, 7.70
- KERNEL: 7.21 to 7.22, 7.45, 7.49, 7.52, 7.53, 7.70
- KRNL32NUC & KRNL32UC: 7.21, 7.21EXT
- KRNL64NUC: 7.21, 7.21EXT, 7.22, 7.22EXT, 7.49
Full note on SAP: SAP Support Launchpad note 2520995
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



