QID 87510
Date Published: 2022-08-22
QID 87510: SAP NetWeaver AS for Java Reverse Tabnabbing Vulnerability
SAP Netweaver Application Server Java (Applications based on WebDynpro Java) versions 7.00, 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allow an attacker to redirect users to a malicious site due to Reverse Tabnabbing vulnerabilities.
Affected Versions
SAP NetWeaver AS for JAVA (Applications based on WebDynpro Java), Versions - 7.00, 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50
QID Detection Logic(s):
Scan initiates HTTP request on Web Server and determines version based on the Server Header.
Successful exploitation of this vulnerability may allow an attacker to redirect victims to redirect to malicious site.
Solution
Customers are advised to follow the SAP Security Advisory for remediation instructions.
Vendor References
CVEs related to QID 87510
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| 2976947 |
|