Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2017-16679 URL Redirection vulnerability in Startup Service, SAP security note 2520995

SAP Note 2520995
SAP Security Note
Medium priority

SAP security note 2520995, "[CVE-2017-16679] URL Redirection vulnerability in Startup Service", is a program error note released on 12.12.2017. Below are the symptom, SAP recommended solution and the affected software components.

ComponentBasis Components > Client/Server Technology > Startup Service
CategoryProgram error
PriorityCorrection with medium priority
TypeSAP Security Note
Version8
StatusReleased for Customer
Released on12.12.2017
LanguageEnglish

Description

Symptom

Startup Service allows an attacker to redirect users to a malicious site due to insufficient URL validation.

Some well-known impacts of URL Redirection vulnerability are:

  • Phishing attacks to steal credentials of the victim
  • Redirect users to untrusted webpages containing malware or similar malicious exploits

Solution

With this fix, the Startup Service does not use information from the request to generate the redirect response. It is no longer possible for an attacker to influence the redirect response.

Action Required: Use Startup Service and hostagent with the patch level specified in this SAP Note or a higher patch level.

Reason and prerequisites

An attacker could influence the content of a redirect response and redirect users to untrusted webpages.

CVSS

Score 5.3 / 10 Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Affected components

  • KRNL64UC: 7.21, 7.21EXT, 7.22, 7.22EXT, 7.49, 7.53, 7.70
  • KERNEL: 7.21 to 7.22, 7.45, 7.49, 7.52, 7.53, 7.70
  • KRNL32NUC & KRNL32UC: 7.21, 7.21EXT
  • KRNL64NUC: 7.21, 7.21EXT, 7.22, 7.22EXT, 7.49

Full note on SAP: SAP Support Launchpad note 2520995

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More