PT-2023-19254 · Sap · Sap Netweaver Application Server For Abap/Abap Platform
Published
2023-02-14
·
Updated
2023-04-12
·
CVE-2023-23853
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
AP NetWeaver Application Server for ABAP and ABAP Platform versions 700, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 789, 790
Description
An unauthenticated attacker can craft a link that, when clicked by an unsuspecting user, can redirect the user to a malicious site. This could potentially read or modify sensitive information or expose the victim to a phishing attack. The issue has no direct impact on availability.
Recommendations
For versions 700, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 789, 790, consider implementing additional security measures to prevent unauthorized redirections, such as validating user-inputted URLs and implementing anti-phishing protections.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sap Netweaver Application Server For Abap/Abap Platform