Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fcph-vwq2-2v5x

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

SAP Web Application Server (WebAS) Kernel before 7.0 allows remote attackers to inject arbitrary bytes into the HTTP response and obtain sensitive authentication information, or have other impacts, via a ";%20" followed by encoded HTTP headers.

SAP Web Application Server (WebAS) Kernel before 7.0 allows remote attackers to inject arbitrary bytes into the HTTP response and obtain sensitive authentication information, or have other impacts, via a ";%20" followed by encoded HTTP headers.

EPSS

Процентиль: 90%
0.05852
Низкий

Дефекты

CWE-94

Связанные уязвимости

nvd
почти 20 лет назад

SAP Web Application Server (WebAS) Kernel before 7.0 allows remote attackers to inject arbitrary bytes into the HTTP response and obtain sensitive authentication information, or have other impacts, via a ";%20" followed by encoded HTTP headers.

EPSS

Процентиль: 90%
0.05852
Низкий

Дефекты

CWE-94