CVE-2006-0731: Medium severity SAP Business Connector vulnerability
Published Feb 16, 2006
·Updated
WmRoot/adapter-index.dsp in SAP Business Connector Core Fix 7 and earlier allows remote attackers to conduct spoofing (phishing) attacks via an absolute URL in the url parameter, which loads the URL inside a frame.
Affected Software
1 affected component
SAP Business Connector<=core_fix_7
Event History
Feb 16, 2006
CVE Published
11:02 AM
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-0731?
CVE-2006-0731 has a medium severity rating that can lead to phishing attacks.
2
How do I fix CVE-2006-0731?
To fix CVE-2006-0731, upgrade to a version of SAP Business Connector later than Core Fix 7.
3
What causes the vulnerability CVE-2006-0731?
CVE-2006-0731 is caused by inadequate validation of the url parameter, allowing an absolute URL to be loaded inside a frame.
4
Who is affected by CVE-2006-0731?
CVE-2006-0731 affects users of SAP Business Connector Core Fix 7 and earlier versions.
5
What type of attacks can CVE-2006-0731 facilitate?
CVE-2006-0731 can facilitate remote spoofing and phishing attacks.