SAP Knowledge Base Article - Preview

3733767 - Vulnerability CVE-2020-26836 and Queries on applicability of Note 2938650

Symptom

  • According to SAP note 2938650 the fixes are applied For ST component 7.2 SP-11 later versions
  • SAP security note 2938650 addresses CVE-2020-26836 on Solution Manager 7.2 (Trace Analysis).
  • Security experts suggest similar behavior may exist in other ABAP systems although the specific Solution Manager note cannot be implemented there.


Read more...

Environment

  • ABAP systems (including Solution Manager 7.2 and other ABAP-based systems)
  • Trace Analysis

Keywords

open redirect, redirecturl, logoff parameter, icf logoff, url redirection, abap, SAP solution manager 7.2, trace analysis, icm, bc-cst-ic, security, cve-2020-26836, external redirect, http redirect, icf configuration , KBA , SV-SMG-DIA-APP-TA , Trace Analysis , Problem

About this page

This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).

Search for additional results

Visit SAP Support Portal's SAP Notes and KBA Search.