ID

VAR-201311-0407


TITLE

SAP Netweaver Web Application Server J2EE SAP Portal Redirect Vulnerability

Trust: 0.6

sources: CNVD: CNVD-2013-14587

DESCRIPTION

SAP NetWeaver is the technical foundation for SAP Business Suite solutions, SAP xApps composite applications, partner solutions, and custom applications. SAP Web Application Server is a web application service program. The input passed to SAP Portal lacks correct validation before being used to redirect users, allowing attackers to build malicious URIs, enticing users to resolve, redirecting user communications to any WEB site, and performing phishing attacks

Trust: 0.72

sources: CNVD: CNVD-2013-14587 // IVD: d8aa377e-1efc-11e6-abef-000c29c66e3d

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 0.8

sources: IVD: d8aa377e-1efc-11e6-abef-000c29c66e3d // CNVD: CNVD-2013-14587

AFFECTED PRODUCTS

vendor:sapmodel:web application serverscope:eqversion:6.x

Trust: 0.8

vendor:sapmodel:netweaverscope:eqversion:7.x

Trust: 0.6

vendor:sapmodel:web application serverscope:eqversion:7.x

Trust: 0.6

vendor:sapmodel:netweaverscope:eqversion:7.x*

Trust: 0.2

vendor:sapmodel:web application serverscope:eqversion:7.x*

Trust: 0.2

sources: IVD: d8aa377e-1efc-11e6-abef-000c29c66e3d // CNVD: CNVD-2013-14587

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2013-14587
value: LOW

Trust: 0.6

IVD: d8aa377e-1efc-11e6-abef-000c29c66e3d
value: LOW

Trust: 0.2

CNVD: CNVD-2013-14587
severity: LOW
baseScore: 2.6
vectorString: AV:N/AC:H/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: HIGH
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 4.9
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

IVD: d8aa377e-1efc-11e6-abef-000c29c66e3d
severity: LOW
baseScore: 2.6
vectorString: AV:N/AC:H/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: HIGH
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 4.9
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.9 [IVD]

Trust: 0.2

sources: IVD: d8aa377e-1efc-11e6-abef-000c29c66e3d // CNVD: CNVD-2013-14587

TYPE

Input validation

Trust: 0.2

sources: IVD: d8aa377e-1efc-11e6-abef-000c29c66e3d

PATCH

title:Patch for SAP Netweaver Web Application Server J2EE SAP Portal Redirection Vulnerabilityurl:https://www.cnvd.org.cn/patchinfo/show/41195

Trust: 0.6

sources: CNVD: CNVD-2013-14587

EXTERNAL IDS

db:CNVDid:CNVD-2013-14587

Trust: 0.8

db:IVDid:D8AA377E-1EFC-11E6-ABEF-000C29C66E3D

Trust: 0.2

sources: IVD: d8aa377e-1efc-11e6-abef-000c29c66e3d // CNVD: CNVD-2013-14587

REFERENCES

url:http://erpscan.com/advisories/erpscan-13-021-sap-portal-unvalidated-redirect/

Trust: 0.6

sources: CNVD: CNVD-2013-14587

SOURCES

db:IVDid:d8aa377e-1efc-11e6-abef-000c29c66e3d
db:CNVDid:CNVD-2013-14587

LAST UPDATE DATE

2022-05-17T02:00:03.211000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2013-14587date:2013-11-25T00:00:00

SOURCES RELEASE DATE

db:IVDid:d8aa377e-1efc-11e6-abef-000c29c66e3ddate:2013-11-21T00:00:00
db:CNVDid:CNVD-2013-14587date:2013-11-21T00:00:00