SAP NetWeaver Open Redirection Vulnerability
BID:100909
Info
SAP NetWeaver Open Redirection Vulnerability
| Bugtraq ID: | 100909 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 12 2017 12:00AM |
| Updated: | Sep 12 2017 12:00AM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
SAP NetWeaver 0 |
| Not Vulnerable: | |
Discussion
SAP NetWeaver Open Redirection Vulnerability
SAP NetWeaver is prone to open-redirection vulnerability
An attacker can leverage this issue by constructing a crafted URI and enticing a user to follow it. When an unsuspecting victim follows the link, they may be redirected to an attacker-controlled site; this may aid in phishing attacks. Other attacks are possible.
SAP NetWeaver is prone to open-redirection vulnerability
An attacker can leverage this issue by constructing a crafted URI and enticing a user to follow it. When an unsuspecting victim follows the link, they may be redirected to an attacker-controlled site; this may aid in phishing attacks. Other attacks are possible.
References
SAP NetWeaver Open Redirection Vulnerability
References:
References:
- SAP Homepage (SAP)
- SAP Security Note 2423540 (SAP)
- SAP Security Patch Day �?? September 2017 (SAP)