Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mqx2-hffm-62vp

Опубликовано: 09 июн. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 4.2

Описание

SAP Fiori Launchpad allows attackers to craft malicious URLs that triggers arbitrary service calls on the Fiori domain, this when opened by the user could compromise accounts by stealing user credentials. Successful exploitation requires adversaries to possess advanced knowledge of the system causing low impact on Confidentiality and Integrity. Availability of the system is no impacted.

SAP Fiori Launchpad allows attackers to craft malicious URLs that triggers arbitrary service calls on the Fiori domain, this when opened by the user could compromise accounts by stealing user credentials. Successful exploitation requires adversaries to possess advanced knowledge of the system causing low impact on Confidentiality and Integrity. Availability of the system is no impacted.

EPSS

Процентиль: 7%
0.00174
Низкий

4.2 Medium

CVSS3

Дефекты

CWE-35

Связанные уязвимости

CVSS3: 4.2
nvd
около 2 месяцев назад

SAP Fiori Launchpad allows attackers to craft malicious URLs that triggers arbitrary service calls on the Fiori domain, this when opened by the user could compromise accounts by stealing user credentials. Successful exploitation requires adversaries to possess advanced knowledge of the system causing low impact on Confidentiality and Integrity. Availability of the system is no impacted.

EPSS

Процентиль: 7%
0.00174
Низкий

4.2 Medium

CVSS3

Дефекты

CWE-35