CVE-2020-6365: Medium severity sap netweaver as for java vulnerability
SAP NetWeaver AS Java, versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, Start Page allows an unauthenticated remote attacker to redirect users to a malicious site due to insufficient reverse tabnabbing URL validation. The attacker could execute phishing attacks to steal credentials of the victim or to redirect users to untrusted web pages containing malware or similar malicious exploits.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-6365?
CVE-2020-6365 is a vulnerability in SAP NetWeaver AS Java versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, and 7.50 that allows an unauthenticated remote attacker to redirect users to a malicious site due to insufficient reverse tabnabbing URL validation.
How severe is CVE-2020-6365?
CVE-2020-6365 has a severity rating of 6.1, which is classified as medium.
How does CVE-2020-6365 affect SAP NetWeaver AS Java?
CVE-2020-6365 affects SAP NetWeaver AS Java versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, and 7.50.
What is reverse tabnabbing?
Reverse tabnabbing is a technique where a malicious website tricks the user into thinking they are interacting with a legitimate website, leading to potential credential theft.
How can I fix CVE-2020-6365?
To fix CVE-2020-6365, apply the necessary patches and updates provided by SAP.