First published: Wed Dec 09 2020(Updated: )
SAP Solution Manager (Trace Analysis), version - 720, allows for misuse of a parameter in the application URL leading to Open Redirect vulnerability, an attacker can enter a link to malicious site which could trick the user to enter credentials or download malicious software, as a parameter in the application URL and share it with the end user who could potentially become a victim of the attack.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP Solution Manager | =7.20 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-26836.
The severity rating of CVE-2020-26836 is medium (6.1).
The affected software is SAP Solution Manager version 7.20.
This vulnerability can lead to an open redirect, allowing attackers to trick users into visiting malicious websites or downloading malicious software.
Yes, there are references available for CVE-2020-26836. Please refer to the following links: http://packetstormsecurity.com/files/163136/SAP-Solution-Manager-7.2-ST-720-Open-Redirection.html, http://seclists.org/fulldisclosure/2021/Jun/25, https://launchpad.support.sap.com/#/notes/2938650.