PT-2018-15592 · Sap · Sap Netweaver

Publicado

2018-11-13

·

Atualizado

2018-12-13

·

CVE-2018-2476

CVSS v3.1

6.1

Média

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions SAP NetWeaver versions 7.30, 7.31, 7.40
Description The issue is due to insufficient URL validation in forums, allowing an attacker to redirect users to a malicious site.
Recommendations For SAP NetWeaver version 7.30, update the URL validation mechanism to prevent malicious redirects. For SAP NetWeaver version 7.31, improve the URL validation process to avoid redirects to unauthorized sites. For SAP NetWeaver version 7.40, enhance the forum's URL validation to prevent attackers from redirecting users to malicious sites.

Correção

Open Redirect

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-2476

Produtos afetados

Sap Netweaver