Description
An unauthenticated attacker in AP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 789, 790, can craft a link which when clicked by an unsuspecting user can be used to redirect a user to a malicious site which could read or modify some sensitive information or expose the victim to a phishing attack. Vulnerability has no direct impact on availability.
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None
Affected products
- SAP / NetWeaver Application Server for ABAP and ABAP Platform700 – 700
- SAP / NetWeaver Application Server for ABAP and ABAP Platform702 – 702
- SAP / NetWeaver Application Server for ABAP and ABAP Platform731 – 731
- SAP / NetWeaver Application Server for ABAP and ABAP Platform740 – 740
- SAP / NetWeaver Application Server for ABAP and ABAP Platform750 – 750
- SAP / NetWeaver Application Server for ABAP and ABAP Platform751 – 751
- SAP / NetWeaver Application Server for ABAP and ABAP Platform752 – 752
- SAP / NetWeaver Application Server for ABAP and ABAP Platform753 – 753
- SAP / NetWeaver Application Server for ABAP and ABAP Platform754 – 754
- SAP / NetWeaver Application Server for ABAP and ABAP Platform755 – 755
- SAP / NetWeaver Application Server for ABAP and ABAP Platform756 – 756
- SAP / NetWeaver Application Server for ABAP and ABAP Platform757 – 757
- SAP / NetWeaver Application Server for ABAP and ABAP Platform789 – 789
- SAP / NetWeaver Application Server for ABAP and ABAP Platform790 – 790