First published: Tue Nov 13 2018(Updated: )
Due to insufficient URL Validation in forums in SAP NetWeaver versions 7.30, 7.31, 7.40, an attacker can redirect users to a malicious site.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP NetWeaver | =7.30 | |
SAP NetWeaver | =7.31 | |
SAP NetWeaver | =7.40 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2018-2476.
The severity of CVE-2018-2476 is medium.
SAP NetWeaver versions 7.30, 7.31, and 7.40 are affected by CVE-2018-2476.
An attacker can redirect users to a malicious site using CVE-2018-2476.
Yes, the following references are available: http://www.securityfocus.com/bid/105898, https://launchpad.support.sap.com/#/notes/2658755, https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=503809832