Link Redirection Vulnerability in SAP NetWeaver Application Server for ABAP
CVE-2023-23853

6.1MEDIUM

Key Information:

Vendor
SAP
Vendor
CVE Published:
14 February 2023

Summary

An unauthenticated attacker can exploit a vulnerability in the SAP NetWeaver Application Server for ABAP, allowing the creation of a malicious link. If clicked by an unsuspecting user, this link redirects them to a harmful site, enabling the attacker to potentially read or alter sensitive information. This redirection could also expose users to phishing attempts, posing significant risks to both user security and data integrity.

Affected Version(s)

NetWeaver Application Server for ABAP and ABAP Platform 700

NetWeaver Application Server for ABAP and ABAP Platform 702

NetWeaver Application Server for ABAP and ABAP Platform 731

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.