Symptom
SAP NetWeaver ABAP ICF endpoint `/sap/bc/echo/` and `/sap/bc/echo/logon_base64` accept password submission via HTTP GET method, transmitting credentials within the URL query string. This creates a security vulnerability where passwords are exposed through:
- Browser history
- Web server logs
- Proxy logs
- Bookmarks
- HTTP referrer headers
Affected URL paths:
- /sap/bc/echo/logon_base64
- /sap/bc/echo/logon_base64/
Security assessment finding: Credentials transmitted in URL parameters instead of HTTP request body increases risk of unauthorized credential exposure and interception through intermediary systems.
Read more...
Environment
- SAP NetWeaver
- SAP NetWeaver Application Server for SAP S/4HANA
- ABAP PLATFORM - Application Server ABAP
Product
Keywords
ICF, Internet Communication Framework, SICF, Service, Services, ICF service, ICF_GDPR, ICF_STD, ICF endpoint security, /sap/bc/echo, HTTP GET method password exposure, credentials in URL query string, browser history vulnerability, proxy logs password exposure, SICF service configuration, production security, diagnostic service deactivation, XSRF protection, SAP NetWeaver security hardening, password transmission security , KBA , BC-MID-ICF-LGN , ICF System Login , Problem
About this page
This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).Search for additional results
Visit SAP Support Portal's SAP Notes and KBA Search.
SAP Knowledge Base Article - Preview