PT-2018-15592 · Sap · Sap Netweaver
Published
2018-11-13
·
Updated
2018-12-13
·
CVE-2018-2476
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
SAP NetWeaver versions 7.30, 7.31, 7.40
Description
The issue is due to insufficient URL validation in forums, allowing an attacker to redirect users to a malicious site.
Recommendations
For SAP NetWeaver version 7.30, update the URL validation mechanism to prevent malicious redirects.
For SAP NetWeaver version 7.31, improve the URL validation process to avoid redirects to unauthorized sites.
For SAP NetWeaver version 7.40, enhance the forum's URL validation to prevent attackers from redirecting users to malicious sites.
Fix
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sap Netweaver