Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p6c6-6r9j-859q

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

SAP NetWeaver Application Server Java(HTTP Service), versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently validate logon group in URLs, resulting in a content spoofing vulnerability when directory listing is enabled.

SAP NetWeaver Application Server Java(HTTP Service), versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently validate logon group in URLs, resulting in a content spoofing vulnerability when directory listing is enabled.

EPSS

Процентиль: 37%
0.00161
Низкий

Дефекты

CWE-290

Связанные уязвимости

CVSS3: 4.3
nvd
почти 5 лет назад

SAP NetWeaver Application Server Java(HTTP Service), versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently validate logon group in URLs, resulting in a content spoofing vulnerability when directory listing is enabled.

EPSS

Процентиль: 37%
0.00161
Низкий

Дефекты

CWE-290