SAP Knowledge Base Article - Preview

3576969 - Security vulnerabilities in error messages related to redirecturl parameter

Symptom

  • The logoff parameter redirecturl is marked as a security vulnerability.
  • The HTTP 500 error message displays sensitive information.
  • The custom error page is not displayed as expected.


Read more...

Environment

  • SAP NetWeaver
  • SAP NetWeaver Application Server for SAP S/4HANA
  • ABAP PLATFORM - Application Server ABAP

Product

ABAP platform all versions ; SAP NetWeaver all versions ; SAP S/4HANA all versions ; SAP Web Application Server for SAP S/4HANA all versions

Keywords

ICF, Internet Communication Framework, SICF, Service, Services, ICF service, logoff parameter, security vulnerability, HTTP 500 error, HTTP_WHITELIST, is/HTTP/show_detailed_errors, icm/HTTP/error_templ_path, ICMERR-EINTERN, ICMERR-EDEFAULT , KBA , BC-MID-ICF , Internet Communication Framework , BC-CST-IC , Internet Communication Manager , BC-MID-ICF-LGN , ICF System Login , Problem

About this page

This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).

Search for additional results

Visit SAP Support Portal's SAP Notes and KBA Search.