ID
VAR-201709-1269
TITLE
SAP NetWeaver Open Redirection Vulnerability
Trust: 0.3
sources:
BID: 100909
DESCRIPTION
SAP NetWeaver is prone to open-redirection vulnerability An attacker can leverage this issue by constructing a crafted URI and enticing a user to follow it. When an unsuspecting victim follows the link, they may be redirected to an attacker-controlled site; this may aid in phishing attacks. Other attacks are possible.
Trust: 0.3
sources:
BID: 100909
AFFECTED PRODUCTS
| vendor: | sap | model: | netweaver | scope: | eq | version: | 0 | Trust: 0.3 |
sources:
BID: 100909
THREAT TYPE
network
Trust: 0.3
sources:
BID: 100909
TYPE
Input Validation Error
Trust: 0.3
sources:
BID: 100909
EXTERNAL IDS
| db: | BID | id: | 100909 | Trust: 0.3 |
sources:
BID: 100909
REFERENCES
| url: | http://www.sap.com/ | Trust: 0.3 |
| url: | https://launchpad.support.sap.com/#/notes/2423540 | Trust: 0.3 |
| url: | https://blogs.sap.com/2017/09/12/sap-security-patch-day-september-2017/ | Trust: 0.3 |
sources:
BID: 100909
CREDITS
The vendor reported this issue.
Trust: 0.3
sources:
BID: 100909
SOURCES
| db: | BID | id: | 100909 |
LAST UPDATE DATE
2022-05-17T02:04:30.743000+00:00
SOURCES UPDATE DATE
| db: | BID | id: | 100909 | date: | 2017-09-12T00:00:00 |
SOURCES RELEASE DATE
| db: | BID | id: | 100909 | date: | 2017-09-12T00:00:00 |