SAP Enterprise Portal – Anonymous Stored Open Redirect
January 26, 2022
IMPACT ON BUSINESS
This URL Redirection vulnerability in SAP Knowledge Management allows remote attackers to redirect users to arbitrary websites and conduct phishing attacks via a URL stored in a component. This gives the attacker the ability to compromise the user’s confidentiality and integrity.
AFFECTED COMPONENTS DESCRIPTION
SAP Enterprise Portal is a web frontend component for SAP Netweaver.
Affected components:
- EP-RUNTIME 7.30
- EP-RUNTIME 7.31
- EP-RUNTIME 7.40
- EP-RUNTIME 7.50
- 04/26/2021: Onapsis sends details to SAP
- 04/29/2021: SAP provides internal ID
- 08/10/2021: SAP releases SAP Note fixing the issue.
Advisory Information
- Public Release Date: 01/26/2022
- Security Advisory ID: ONAPSIS-2021-0024
- Vulnerability Submission ID: 884
- Researcher(s): Yvan Genuer
- Vendor: SAP
- Vulnerability Class: |LS|CWE-601|RS| URL Redirection to Untrusted Site (‘Open Redirect’)
- CVSS v3 score: 6.1 AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- Severity: Medium
- CVE: CVE-2021-337057
- Vendor patch Information: SAP Security Note 3076399
