SAP Startup Service CVE-2017-16679 URL Redirection Vulnerability
BID:102157
Info
SAP Startup Service CVE-2017-16679 URL Redirection Vulnerability
| Bugtraq ID: | 102157 |
| Class: | Input Validation Error |
| CVE: |
CVE-2017-16679 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 12 2017 12:00AM |
| Updated: | Dec 19 2017 10:38PM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
SAP Startup Service 0 SAP KERNEL64Unicode 7.22EXT SAP KERNEL64Unicode 7.22 SAP KERNEL64Unicode 7.21EXT SAP KERNEL64Unicode 7.21 SAP KERNEL64NUC 7.22EXT SAP KERNEL64NUC 7.22 SAP KERNEL64NUC 7.21EXT SAP KERNEL64NUC 7.21 SAP KERNEL32Unicode 7.22EXT SAP KERNEL32Unicode 7.22 SAP KERNEL32Unicode 7.21EXT SAP KERNEL32Unicode 7.21 SAP KERNEL32NUC 7.22EXT SAP KERNEL32NUC 7.22 SAP KERNEL32NUC 7.21EXT SAP KERNEL32NUC 7.21 SAP Kernel 7.52 SAP Kernel 7.49 SAP Kernel 7.45 SAP Kernel 7.22 SAP Kernel 7.21 |
| Not Vulnerable: | |
Discussion
SAP Startup Service CVE-2017-16679 URL Redirection Vulnerability
SAP Startup Service is prone to a remote URL-redirection vulnerability.
An attacker can leverage this issue by constructing a URI that includes a malicious site redirection. When an unsuspecting victim follows the URI, they may be redirected to an attacker-controlled site; this may aid in phishing attacks.
SAP Startup Service is prone to a remote URL-redirection vulnerability.
An attacker can leverage this issue by constructing a URI that includes a malicious site redirection. When an unsuspecting victim follows the URI, they may be redirected to an attacker-controlled site; this may aid in phishing attacks.
Exploit / POC
SAP Startup Service CVE-2017-16679 URL Redirection Vulnerability
An attacker can exploit this issue by enticing an unsuspecting victim into following a malicious URI.
An attacker can exploit this issue by enticing an unsuspecting victim into following a malicious URI.
Solution / Fix
SAP Startup Service CVE-2017-16679 URL Redirection Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
SAP Startup Service CVE-2017-16679 URL Redirection Vulnerability
References:
References:
- SAP Homepage (SAP)
- SAP Security Note 2520995 (SAP)
- SAP Security Patch Day �?? December 2017 (SAP)