Remote Logout and Redirection Vulnerability in SAP Web Application Server
CVE-2005-3634
Currently unrated
What is CVE-2005-3634?
The frameset.htm in the BSP runtime of SAP Web Application Server versions 6.10 through 7.00 allows remote attackers to exploit session management weaknesses. By sending a specially crafted close command through the sap-sessioncmd parameter, they can force user logout and redirect users to arbitrary URLs specified in the sap-exiturl parameter. This vulnerability exposes users to potential phishing attacks and unauthorized session hijacking, highlighting the need for prompt security measures.
References
Timeline
Vulnerability published
Vulnerability Reserved