Описание
SAP Web Application Server (WebAS) Kernel before 7.0 allows remote attackers to inject arbitrary bytes into the HTTP response and obtain sensitive authentication information, or have other impacts, via a ";%20" followed by encoded HTTP headers.
Ссылки
- Vendor Advisory
- Vendor Advisory
- Vendor Advisory
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1
Одно из
cpe:2.3:a:sap:sap_web_application_server:6.10:*:*:*:*:*:*:*
cpe:2.3:a:sap:sap_web_application_server:6.20:*:*:*:*:*:*:*
cpe:2.3:a:sap:sap_web_application_server:6.40:*:*:*:*:*:*:*
EPSS
Процентиль: 90%
0.05852
Низкий
6.4 Medium
CVSS2
Дефекты
CWE-94
Связанные уязвимости
github
почти 4 года назад
SAP Web Application Server (WebAS) Kernel before 7.0 allows remote attackers to inject arbitrary bytes into the HTTP response and obtain sensitive authentication information, or have other impacts, via a ";%20" followed by encoded HTTP headers.
EPSS
Процентиль: 90%
0.05852
Низкий
6.4 Medium
CVSS2
Дефекты
CWE-94