CVE-2017-16679
URL redirection vulnerability in SAP's Startup Service, SAP KERNEL 32 NUC, SAP KERNEL 32 Unicode, SAP KERNEL 64 NUC, SAP KERNEL 64 Unicode 7.21, 7.21EXT, 7.22 and 7.22EXT; SAP KERNEL 7.21, 7.22, 7.45, 7.49 and 7.52, that allows an attacker to redirect…
Does this matter?
Lower severity and a low EPSS score (0.87%). Track it; it rarely justifies an emergency change on its own.
Description
URL redirection vulnerability in SAP's Startup Service, SAP KERNEL 32 NUC, SAP KERNEL 32 Unicode, SAP KERNEL 64 NUC, SAP KERNEL 64 Unicode 7.21, 7.21EXT, 7.22 and 7.22EXT; SAP KERNEL 7.21, 7.22, 7.45, 7.49 and 7.52, that allows an attacker to redirect users to a malicious site.
- CVSS 3.0
- 6.1 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.87% probability · 57th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-601
- Affected
- sap/sap kernel
- Source
- cna@sap.com
References
- http://www.securityfocus.com/bid/102157Third Party Advisory, VDB Entry
- https://blogs.sap.com/2017/12/12/sap-security-patch-day-december-2017/Issue Tracking, Vendor Advisory
- https://launchpad.support.sap.com/#/notes/2520995Permissions Required, Vendor Advisory
- http://www.securityfocus.com/bid/102157Third Party Advisory, VDB Entry
- https://blogs.sap.com/2017/12/12/sap-security-patch-day-december-2017/Issue Tracking, Vendor Advisory
- https://launchpad.support.sap.com/#/notes/2520995Permissions Required, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.