Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5hhx-v396-wch6

Опубликовано: 13 авг. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 4.7

Описание

SAP NetWeaver Application Server ABAP allows an unauthenticated attacker to craft a URL link that could bypass allowlist controls. Depending on the web applications provided by this server, the attacker might inject CSS code or links into the web application that could allow the attacker to read or modify information. There is no impact on availability of application.

SAP NetWeaver Application Server ABAP allows an unauthenticated attacker to craft a URL link that could bypass allowlist controls. Depending on the web applications provided by this server, the attacker might inject CSS code or links into the web application that could allow the attacker to read or modify information. There is no impact on availability of application.

EPSS

Процентиль: 36%
0.00152
Низкий

4.7 Medium

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 4.7
nvd
больше 1 года назад

SAP NetWeaver Application Server ABAP allows an unauthenticated attacker to craft a URL link that could bypass allowlist controls. Depending on the web applications provided by this server, the attacker might inject CSS code or links into the web application that could allow the attacker to read or modify information. There is no impact on availability of application.

CVSS3: 4.7
fstec
больше 1 года назад

Уязвимость программной интеграционной платформы SAP NetWeaver AS ABAP, связанная с недостатками разграничения доступа, позволяющая нарушителю получить доступ на чтение, изменение или удаление данных

EPSS

Процентиль: 36%
0.00152
Низкий

4.7 Medium

CVSS3

Дефекты

CWE-284