CVE-2014-4159: Medium severity SAP Supplier Relationship Management vulnerability
Published Jun 13, 2014
·Updated
Open redirect vulnerability in in la/umTestSSO.jsp in SAP Supplier Relationship Management (SRM) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the url parameter.
Affected Software
1 affected component
SAP Supplier Relationship Management
Event History
Jun 13, 2014
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Data Sourced
via NVD·02:55 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2014-4159?
CVE-2014-4159 has been rated as medium severity due to its potential for phishing attacks.
2
How do I fix CVE-2014-4159?
To fix CVE-2014-4159, update SAP Supplier Relationship Management to the latest version that addresses this vulnerability.
3
Can CVE-2014-4159 be exploited remotely?
Yes, CVE-2014-4159 can be exploited remotely since it involves an open redirect vulnerability.
4
What are the consequences of CVE-2014-4159?
Exploitation of CVE-2014-4159 allows attackers to redirect users to malicious sites, increasing the risk of phishing.
5
Which software is affected by CVE-2014-4159?
CVE-2014-4159 affects SAP Supplier Relationship Management across all versions.