SAP Web Application Server URI Redirection Vulnerability
BID:15362
Info
SAP Web Application Server URI Redirection Vulnerability
| Bugtraq ID: | 15362 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 09 2005 12:00AM |
| Updated: | Nov 09 2005 12:00AM |
| Credit: | Leandro Meiners <[email protected]> is credited with the discovery of this vulnerability. |
| Vulnerable: |
SAP Web Application Server 7.0 SAP Web Application Server 6.40 SAP Web Application Server 6.20 SAP Web Application Server 6.10 |
| Not Vulnerable: | |
Discussion
SAP Web Application Server URI Redirection Vulnerability
SAP Web Application Server is reported prone to a remote URI redirection vulnerability.
It is reported that an attacker can exploit this issue by supplying the URI of a malicious site through the 'sap-exiturl' parameter.
A successful attack may result in various attacks including theft of cookie-based authentication credentials. An attacker may also be able to exploit this vulnerability to enhance phishing style attacks.
This issue only affects the BSP runtime of SAP WAS.
SAP Web Application Server is reported prone to a remote URI redirection vulnerability.
It is reported that an attacker can exploit this issue by supplying the URI of a malicious site through the 'sap-exiturl' parameter.
A successful attack may result in various attacks including theft of cookie-based authentication credentials. An attacker may also be able to exploit this vulnerability to enhance phishing style attacks.
This issue only affects the BSP runtime of SAP WAS.
Exploit / POC
SAP Web Application Server URI Redirection Vulnerability
An exploit is not required.
The following proof of concept URI is available:
http://www.example.com/sap/bc/BSp/sap/menu/fameset.htm?sap--essioncmd=close&sapexiturl=http%3a%2f%2fwww.example.com
An exploit is not required.
The following proof of concept URI is available:
http://www.example.com/sap/bc/BSp/sap/menu/fameset.htm?sap--essioncmd=close&sapexiturl=http%3a%2f%2fwww.example.com
Solution / Fix
SAP Web Application Server URI Redirection Vulnerability
Solution:
The vendor has released solutions and patch information regarding this issue. Users are advised to contact the vendor for further information.
Solution:
The vendor has released solutions and patch information regarding this issue. Users are advised to contact the vendor for further information.
References
SAP Web Application Server URI Redirection Vulnerability
References:
References:
- SAP Homepage (SAP)
- CYBSEC - Security Advisory: Phishing Vector in SAP WAS (Leandro Meiners
)