CVE-2023-40306: URL Redirection vulnerability in SAP S/4HANA (Manage Catalog Items and Cross-Catalog search)
Published Sep 8, 2023
·Updated
SAP S/4HANA Manage Catalog Items and Cross-Catalog searches Fiori apps allow an attacker to redirect users to a malicious site due to insufficient URL validation. As a result, it may have a slight impact on confidentiality and integrity.
Affected Software
4 affected components
SAP S\/4hana=103
SAP S\/4hana=104
SAP S\/4hana=105
SAP S\/4hana=106
Event History
Sep 8, 2023
CVE Published
via MITRE·09:05 PM
Data Sourced
via MITRE·09:05 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2023-40306.
2
What is the severity of CVE-2023-40306?
The severity of CVE-2023-40306 is medium with a severity value of 6.1.
3
Which SAP S/4HANA versions are affected by CVE-2023-40306?
CVE-2023-40306 affects SAP S/4HANA versions 103, 104, 105, and 106.
4
What is the impact of CVE-2023-40306?
CVE-2023-40306 may have a slight impact on confidentiality and integrity.
5
How can I fix CVE-2023-40306?
To fix CVE-2023-40306, apply the recommended security patches provided by SAP.