CVE-2013-6814: Input Validation
The J2EE Engine in SAP NetWeaver 6.40, 7.02, and earlier allows remote attackers to redirect users to arbitrary web sites, conduct phishing attacks, and obtain sensitive information (cookies and SAPPASSPORT) via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-6814?
CVE-2013-6814 is considered a high severity vulnerability that allows remote attackers to conduct phishing attacks.
How do I fix CVE-2013-6814?
To mitigate CVE-2013-6814, upgrade SAP NetWeaver to a version later than 7.02 and apply all relevant security patches.
What are the potential impacts of CVE-2013-6814?
The potential impacts of CVE-2013-6814 include unauthorized redirection of users and exposure of sensitive information like cookies and SAPPASSPORT.
Which versions of SAP NetWeaver are affected by CVE-2013-6814?
CVE-2013-6814 affects SAP NetWeaver versions up to and including 7.02 and version 6.4.
Can CVE-2013-6814 be exploited remotely?
Yes, CVE-2013-6814 can be exploited remotely, allowing attackers to redirect users to arbitrary websites.