SAP Knowledge Base Article - Preview

3639523 - Host Header injection in Cloud Integration iFlow

Symptom

  • A potential Host Header Injection issue was observed when an HTTP request to an integration flow resulted in an unexpected 301 Redirect response.
  • The concern was that manipulating the Host header could expose the application to injection-based attacks.


Read more...

Environment

  • Cloud Integration
  • Integration Suite

Product

Cloud Integration all versions ; SAP Integration Suite all versions

Keywords

Cloud Integration, Integration Suite, CPI, HCI, host header injection, http header, security scan, 301 redirect, HAProxy, BTP CF, CPI, false positive, load balancer, domain validation, integration flow, security misconfiguration, application gateway, redirect loop, vulnerability report , KBA , LOD-HCI-PI-CON-HTP , HTTP Adapter , Problem

About this page

This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).

Search for additional results

Visit SAP Support Portal's SAP Notes and KBA Search.