Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9v9g-4ghw-xrxx

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

SAP Fiori Launchpad (News tile Application), versions - 750,751,752,753,754,755, allows an unauthorized attacker to send a crafted request to a vulnerable web application. It is usually used to target internal systems behind firewalls that are normally inaccessible to an attacker from the external network to retrieve sensitive / confidential resources which are otherwise restricted for internal usage only, resulting in a Server-Side Request Forgery vulnerability.

SAP Fiori Launchpad (News tile Application), versions - 750,751,752,753,754,755, allows an unauthorized attacker to send a crafted request to a vulnerable web application. It is usually used to target internal systems behind firewalls that are normally inaccessible to an attacker from the external network to retrieve sensitive / confidential resources which are otherwise restricted for internal usage only, resulting in a Server-Side Request Forgery vulnerability.

EPSS

Процентиль: 51%
0.00276
Низкий

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 8.6
nvd
около 5 лет назад

SAP Fiori Launchpad (News tile Application), versions - 750,751,752,753,754,755, allows an unauthorized attacker to send a crafted request to a vulnerable web application. It is usually used to target internal systems behind firewalls that are normally inaccessible to an attacker from the external network to retrieve sensitive / confidential resources which are otherwise restricted for internal usage only, resulting in a Server-Side Request Forgery vulnerability.

EPSS

Процентиль: 51%
0.00276
Низкий

Дефекты

CWE-918