PT-2023-19254 · Sap · Sap Netweaver Application Server For Abap/Abap Platform

Published

2023-02-14

·

Updated

2023-04-12

·

CVE-2023-23853

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions AP NetWeaver Application Server for ABAP and ABAP Platform versions 700, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 789, 790
Description An unauthenticated attacker can craft a link that, when clicked by an unsuspecting user, can redirect the user to a malicious site. This could potentially read or modify sensitive information or expose the victim to a phishing attack. The issue has no direct impact on availability.
Recommendations For versions 700, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 789, 790, consider implementing additional security measures to prevent unauthorized redirections, such as validating user-inputted URLs and implementing anti-phishing protections. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Open Redirect

Weakness Enumeration

Related Identifiers

CVE-2023-23853

Affected Products

Sap Netweaver Application Server For Abap/Abap Platform