QID 87510

Date Published: 2022-08-22

QID 87510: SAP NetWeaver AS for Java Reverse Tabnabbing Vulnerability

SAP Netweaver Application Server Java (Applications based on WebDynpro Java) versions 7.00, 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allow an attacker to redirect users to a malicious site due to Reverse Tabnabbing vulnerabilities.

Affected Versions
SAP NetWeaver AS for JAVA (Applications based on WebDynpro Java), Versions - 7.00, 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50

QID Detection Logic(s):
Scan initiates HTTP request on Web Server and determines version based on the Server Header.

Successful exploitation of this vulnerability may allow an attacker to redirect victims to redirect to malicious site.

  • CVSS V3 rated as High - 6.1 severity.
  • CVSS V2 rated as Medium - 5.8 severity.
  • Solution
    Customers are advised to follow the SAP Security Advisory for remediation instructions.
    Vendor References

    CVEs related to QID 87510

    Software Advisories
    Advisory ID Software Component Link
    2976947 URL Logo launchpad.support.sap.com/#/notes/2976947