Advisory
A note with CVSS 3.4 for component BC-FES-CTL was released by SAP on 11.05.2021. The correction/advisory 3023078 was described with "[CVE-2021-27612] SAP GUI for Windows is vulnerable to redirect users to an untrusted website" and affects the system type SAP GUI / Frontend.
A workaround does not exist, according to SAP Security Advisory team. It is advisable to implement the correction as monthly patch process .
The vulnerability addressed is insufficient security function within SAP GUI / Frontend.
Risk specification
SAP GUI for Windows forwards users to a malicious website containing malware or leads to phishing attacks.Solution
When a user is directed to an external website and declines to download content an empty page will be displayed correctly.
- 9.0 [CVE-2023-0014] Capture-replay vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform
- 8.5 [CVE-2022-41268] Privilege escalation vulnerability in SAP Business Planning and Consolidation
- 6.7 [CVE-2022-35295] Privilege Escalation Vulnerability in SAPOSCOL on Unix
- 6.5 Information Disclosure vulnerability in SAP Business Client
- 6.3 [CVE-2021-21472] Server password not set during installation of SAP NetWeaver Master Data Management 7.1