SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2005-3634

frameset.htm in the BSP runtime in SAP Web Application Server (WAS) 6.10 through 7.00 allows remote attackers to log users out and redirect them to arbitrary web sites via a close command in the sap-sessioncmd parameter and a URL in the sap-exiturl…

MEDIUM 5.0EPSS 17.8%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 17.8%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.

Description

frameset.htm in the BSP runtime in SAP Web Application Server (WAS) 6.10 through 7.00 allows remote attackers to log users out and redirect them to arbitrary web sites via a close command in the sap-sessioncmd parameter and a URL in the sap-exiturl parameter.

CVSS 2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
EPSS
17.76% probability · 97th percentile
CISA KEV
Not listed
Affected
sap/sap web application server
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.