CVE-2023-23855: Medium severity sap netweaver solution manager vulnerability
SAP Solution Manager - version 720, allows an authenticated attacker to redirect users to a malicious site due to insufficient URL validation. A successful attack could lead an attacker to read or modify the information or expose the user to a phishing attack. As a result, it has a low impact to confidentiality, integrity and availability.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this SAP Solution Manager issue?
The vulnerability ID for this SAP Solution Manager issue is CVE-2023-23855.
What is the severity rating of CVE-2023-23855?
CVE-2023-23855 has a severity rating of medium.
What is the impact of CVE-2023-23855?
CVE-2023-23855 can allow an authenticated attacker to redirect users to a malicious site, potentially leading to unauthorized information access, modification, or phishing attacks.
What version of SAP Solution Manager is affected by CVE-2023-23855?
SAP Solution Manager version 720 is affected by CVE-2023-23855.
Are there any references available for CVE-2023-23855?
Yes, you can find references for CVE-2023-23855 at these links: [Reference 1](https://launchpad.support.sap.com/#/notes/3270509), [Reference 2](https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html).