URL Redirection Vulnerability in SAP NetWeaver ABAP Server and Platform
CVE-2022-28215
4.7MEDIUM
Key Information:
- Vendor
SAP
- Vendor
- CVE Published:
- 12 April 2022
What is CVE-2022-28215?
The SAP NetWeaver ABAP Server and ABAP Platform are susceptible to a URL redirection vulnerability, enabling unauthenticated attackers to redirect users to harmful sites. This issue arises from inadequate validation within URLs, potentially resulting in users being deceived into divulging sensitive information.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
SAP NetWeaver ABAP Server and ABAP Platform 740
SAP NetWeaver ABAP Server and ABAP Platform 750
SAP NetWeaver ABAP Server and ABAP Platform 787
References
CVSS V3.1
Score:
4.7
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved