CVE-2020-6215
SAP NetWeaver AS ABAP Business Server Pages Test Application IT00, versions 700, 701, 702, 730, 731, 740, 750, 751, 752, 753, 754, allows an attacker to redirect users to a malicious site due to insufficient URL validation and steal credentials of the…
Does this matter?
Lower severity and a low EPSS score (1.56%). Track it; it rarely justifies an emergency change on its own.
Description
SAP NetWeaver AS ABAP Business Server Pages Test Application IT00, versions 700, 701, 702, 730, 731, 740, 750, 751, 752, 753, 754, allows an attacker to redirect users to a malicious site due to insufficient URL validation and steal credentials of the victim, leading to URL Redirection vulnerability.
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 1.56% probability · 74th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-601
- Affected
- sap/netweaver as abap business server pages
- Source
- cna@sap.com
References
- http://packetstormsecurity.com/files/174985/SAP-Application-Server-ABAP-Open-Redirection.html
- http://seclists.org/fulldisclosure/2023/Oct/13
- https://launchpad.support.sap.com/#/notes/2872782Permissions Required, Vendor Advisory
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=544214202Vendor Advisory
- http://packetstormsecurity.com/files/174985/SAP-Application-Server-ABAP-Open-Redirection.html
- http://seclists.org/fulldisclosure/2023/Oct/13
- https://launchpad.support.sap.com/#/notes/2872782Permissions Required, Vendor Advisory
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=544214202Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.