SAP Knowledge Base Article - Preview

3783598 - ICF /sap/bc/echo/logon_base64 Endpoint Accepts Password Submission via HTTP GET Method – Security Risk

Symptom

SAP NetWeaver ABAP ICF endpoint `/sap/bc/echo/` and `/sap/bc/echo/logon_base64` accept password submission via HTTP GET method, transmitting credentials within the URL query string. This creates a security vulnerability where passwords are exposed through:

  • Browser history
  • Web server logs
  • Proxy logs
  • Bookmarks
  • HTTP referrer headers

Affected URL paths:

  • /sap/bc/echo/logon_base64
  • /sap/bc/echo/logon_base64/

Security assessment finding: Credentials transmitted in URL parameters instead of HTTP request body increases risk of unauthorized credential exposure and interception through intermediary systems.


Read more...

Environment

  • SAP NetWeaver
  • SAP NetWeaver Application Server for SAP S/4HANA
  • ABAP PLATFORM - Application Server ABAP

Product

ABAP platform all versions ; SAP NetWeaver all versions ; SAP Web Application Server for SAP S/4HANA all versions

Keywords

ICF, Internet Communication Framework, SICF, Service, Services, ICF service, ICF_GDPR, ICF_STD, ICF endpoint security, /sap/bc/echo, HTTP GET method password exposure, credentials in URL query string, browser history vulnerability, proxy logs password exposure, SICF service configuration, production security, diagnostic service deactivation, XSRF protection, SAP NetWeaver security hardening, password transmission security , KBA , BC-MID-ICF-LGN , ICF System Login , Problem

About this page

This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).

Search for additional results

Visit SAP Support Portal's SAP Notes and KBA Search.