Open Redirect Vulnerability in SAP Biller Direct
CVE-2022-41207

6.1MEDIUM

Key Information:

Vendor
SAP
Vendor
CVE Published:
8 November 2022

Summary

The vulnerability in SAP Biller Direct allows an unauthenticated attacker to exploit unsanitized parameters to create a seemingly legitimate URL. When an unsuspecting victim clicks this link, they are redirected to a malicious site controlled by the attacker. This redirection can lead to the disclosure or unauthorized modification of sensitive information from the victim's interactions. It is crucial for users of SAP Biller Direct to remain vigilant and implement necessary security measures to avoid falling prey to such attacks.

Affected Version(s)

SAP Biller Direct = 635 = 635

SAP Biller Direct = 750 = 750

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
🍪 This website uses cookies, like every other website on the internet 😕 By using our website, you consent to the use of cookies.