cbcvebase.
CVE-2020-6215
published 2020-04-14

CVE-2020-6215: SAP NetWeaver AS ABAP Business Server Pages Test Application IT00, versions 700, 701, 702, 730, 731, 740, 750, 751, 752, 753, 754, allows an attacker to…

medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
SAP NetWeaver AS ABAP Business Server Pages Test Application IT00, versions 700, 701, 702, 730, 731, 740, 750, 751, 752, 753, 754, allows an attacker to redirect users to a malicious site due to insufficient URL validation and steal credentials of the victim, leading to URL Redirection vulnerability.

Affected

22 ranges
VendorProductVersion rangeFixed in
sapnetweaver_as_abap_business_server_pages
sapnetweaver_as_abap_business_server_pages
sapnetweaver_as_abap_business_server_pages
sapnetweaver_as_abap_business_server_pages
sapnetweaver_as_abap_business_server_pages
sapnetweaver_as_abap_business_server_pages
sapnetweaver_as_abap_business_server_pages
sapnetweaver_as_abap_business_server_pages
sapnetweaver_as_abap_business_server_pages
sapnetweaver_as_abap_business_server_pages
sapnetweaver_as_abap_business_server_pages
sap_sesap_netweaver_as_abap< 700700
sap_sesap_netweaver_as_abap< 701701
sap_sesap_netweaver_as_abap< 702702
sap_sesap_netweaver_as_abap< 730730
sap_sesap_netweaver_as_abap< 731731
sap_sesap_netweaver_as_abap< 740740
sap_sesap_netweaver_as_abap< 750750
sap_sesap_netweaver_as_abap< 751751
sap_sesap_netweaver_as_abap< 752752
sap_sesap_netweaver_as_abap< 753753
sap_sesap_netweaver_as_abap< 754754