CVE-2022-28215

4.7MEDIUM

Key Information:

Vendor
SAP
Vendor
CVE Published:
12 April 2022

Summary

SAP NetWeaver ABAP Server and ABAP Platform - versions 740, 750, 787, allows an unauthenticated attacker to redirect users to a malicious site due to insufficient URL validation. This could lead to the user being tricked to disclose personal information.

Affected Version(s)

SAP NetWeaver ABAP Server and ABAP Platform 740

SAP NetWeaver ABAP Server and ABAP Platform 750

SAP NetWeaver ABAP Server and ABAP Platform 787

References

CVSS V3.1

Score:
4.7
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.