Remote Logout and Redirection Vulnerability in SAP Web Application Server
CVE-2005-3634

Currently unrated

Key Information:

Vendor

SAP

Vendor
CVE Published:
16 November 2005

What is CVE-2005-3634?

The frameset.htm in the BSP runtime of SAP Web Application Server versions 6.10 through 7.00 allows remote attackers to exploit session management weaknesses. By sending a specially crafted close command through the sap-sessioncmd parameter, they can force user logout and redirect users to arbitrary URLs specified in the sap-exiturl parameter. This vulnerability exposes users to potential phishing attacks and unauthorized session hijacking, highlighting the need for prompt security measures.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.