PT-2018-15592 · Sap · Sap Netweaver

Published

2018-11-13

·

Updated

2018-12-13

·

CVE-2018-2476

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions SAP NetWeaver versions 7.30, 7.31, 7.40
Description The issue is due to insufficient URL validation in forums, allowing an attacker to redirect users to a malicious site.
Recommendations For SAP NetWeaver version 7.30, update the URL validation mechanism to prevent malicious redirects. For SAP NetWeaver version 7.31, improve the URL validation process to avoid redirects to unauthorized sites. For SAP NetWeaver version 7.40, enhance the forum's URL validation to prevent attackers from redirecting users to malicious sites.

Fix

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-2476

Affected Products

Sap Netweaver