CVE-2022-28215: Medium severity sap netweaver as abap vulnerability
SAP NetWeaver ABAP Server and ABAP Platform - versions 740, 750, 787, allows an unauthenticated attacker to redirect users to a malicious site due to insufficient URL validation. This could lead to the user being tricked to disclose personal information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-28215?
The severity of CVE-2022-28215 is medium with a CVSS score of 4.7.
Which versions of SAP NetWeaver ABAP Server and ABAP Platform are affected by CVE-2022-28215?
Versions 740, 750, and 787 of SAP NetWeaver ABAP Server and ABAP Platform are affected by CVE-2022-28215.
How can an attacker exploit CVE-2022-28215?
An unauthenticated attacker can exploit CVE-2022-28215 by redirecting users to a malicious site through insufficient URL validation.
What is the potential impact of CVE-2022-28215?
The potential impact of CVE-2022-28215 is that users can be tricked into disclosing personal information.
Where can I find more information about CVE-2022-28215?
You can find more information about CVE-2022-28215 in the SAP Security Note 3165333 and the SAP advisory document.