CVE-2020-6365

MEDIUM

SAP NetWeaver AS Java - Open Redirect

Title source: llm
STIX 2.1

Description

SAP NetWeaver AS Java, versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, Start Page allows an unauthenticated remote attacker to redirect users to a malicious site due to insufficient reverse tabnabbing URL validation. The attacker could execute phishing attacks to steal credentials of the victim or to redirect users to untrusted web pages containing malware or similar malicious exploits.

References (2)

Core 2
Core References
Permissions Required, Vendor Advisory x_refsource_misc
https://launchpad.support.sap.com/#/notes/2969828

Scores

CVSS v3 6.1
EPSS 0.0021
EPSS Percentile 43.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-601
Status published
Products (7)
sap/netweaver_application_server_java 7.10
sap/netweaver_application_server_java 7.11
sap/netweaver_application_server_java 7.20
sap/netweaver_application_server_java 7.30
sap/netweaver_application_server_java 7.31
sap/netweaver_application_server_java 7.40
sap/netweaver_application_server_java 7.50
Published Oct 15, 2020
Tracked Since Feb 18, 2026