Advisory
A note with CVSS 7.6 for component MOB-FC was released by SAP on 10.08.2021. The correction/advisory 3067219 was described with "[CVE-2021-33699] Task Hijacking in SAP Fiori Client Native Mobile for Android" and affects the system type SAP Fiori Client Android.
A workaround exists, according to SAP Security Advisory team. It is advisable to implement the correction as monthly patch process.
The vulnerability addressed is task hijacking within SAP Fiori Client Android.
Risk specification
An attacker that managed to install a malicious application on an Android Phone running the Fiori native client could highjack the application task and thereby be able to get access to user inputs and sensitive information.Solution
The Applications AndroidManifest.xml was updated to include taskAffinity = "", to no longer allow Task Highjacking Although an alternative solution exists, it is advisable to apply the correction! This is the workaround, which was suggested by the SAP security experts: "For customer who is using Cloud Build service to build the customized Fiori Client, they can download the project file and set taskAffinity="", then rebuild the customized Fiori Client locally. For customer who is using WebIDE to build the customized Fiori Client, they should set taskAffinity to empty string via modifying config.xml for their cordova project in webIDE. And then perform a rebuild action from WebIDE.For customer who is using CLI to build the customized Fiori Client, they can modify the taskAffinity="" and rebuild customized Fiori Client.".
The advisory is valid for
- KAPSEL_ENTERPRISE_BROWSER 1.15
- KAPSEL_SDK 3.2