Advisory
A note with CVSS 3.4 for component BC-FES-CTL was released by SAP on 11.05.2021. The correction/advisory 3023078 was described with "[CVE-2021-27612] SAP GUI for Windows is vulnerable to redirect users to an untrusted website" and affects the system type SAP GUI / Frontend.
A workaround does not exist, according to SAP Security Advisory team. It is advisable to implement the correction as monthly patch process .
The vulnerability addressed is insufficient security function within SAP GUI / Frontend.
Risk specification
SAP GUI for Windows forwards users to a malicious website containing malware or leads to phishing attacks.
Solution
When a user is directed to an external website and declines to download content an empty page will be displayed correctly.
