CVE-2005-3634
frameset.htm in the BSP runtime in SAP Web Application Server (WAS) 6.10 through 7.00 allows remote attackers to log users out and redirect them to arbitrary web sites via a close command in the sap-sessioncmd parameter and a URL in the sap-exiturl…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 17.8%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
frameset.htm in the BSP runtime in SAP Web Application Server (WAS) 6.10 through 7.00 allows remote attackers to log users out and redirect them to arbitrary web sites via a close command in the sap-sessioncmd parameter and a URL in the sap-exiturl parameter.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
- EPSS
- 17.76% probability · 97th percentile
- CISA KEV
- Not listed
- Affected
- sap/sap web application server
- Source
- cve@mitre.org
References
- http://marc.info/?l=bugtraq&m=113156525006667&w=2
- http://secunia.com/advisories/17515/Vendor Advisory
- http://securityreason.com/securityalert/163
- http://www.cybsec.com/vuln/CYBSEC_Security_Advisory_Multiple_XSS_in_SAP_WAS.pdf
- http://www.securityfocus.com/bid/15362Exploit
- http://www.securitytracker.com/alerts/2005/Nov/1015174.htmlVendor Advisory
- http://www.vupen.com/english/advisories/2005/2361
- https://exchange.xforce.ibmcloud.com/vulnerabilities/23031
- http://marc.info/?l=bugtraq&m=113156525006667&w=2
- http://secunia.com/advisories/17515/Vendor Advisory
- http://securityreason.com/securityalert/163
- http://www.cybsec.com/vuln/CYBSEC_Security_Advisory_Multiple_XSS_in_SAP_WAS.pdf
- http://www.securityfocus.com/bid/15362Exploit
- http://www.securitytracker.com/alerts/2005/Nov/1015174.htmlVendor Advisory
- http://www.vupen.com/english/advisories/2005/2361
- https://exchange.xforce.ibmcloud.com/vulnerabilities/23031
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.