CVE-2005-3634
Last modified
CVE-2005-3634 is a vulnerability of currently unknown severity. frameset.htm in the BSP runtime in SAP Web Application Server (WAS) 6.10 through 7.00 allows remote attackers to log users out and redirect them to arbitrary web sites via a close command in the sap-sessioncmd parameter and a URL in the sap-exiturl parameter.. EPSS estimates a 19.38% chance of exploitation in the next 30 days.
Description
frameset.htm in the BSP runtime in SAP Web Application Server (WAS) 6.10 through 7.00 allows remote attackers to log users out and redirect them to arbitrary web sites via a close command in the sap-sessioncmd parameter and a URL in the sap-exiturl parameter.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Sap | Sap Web Application Server | 6.10 |
| Sap | Sap Web Application Server | 6.20 |
| Sap | Sap Web Application Server | 6.40 |
| Sap | Sap Web Application Server | 7.0 |
References
- http://secunia.com/advisories/17515/Vendor Advisory
- http://www.securitytracker.com/alerts/2005/Nov/1015174.htmlVendor Advisory
- http://secunia.com/advisories/17515/Vendor Advisory
- http://www.securitytracker.com/alerts/2005/Nov/1015174.htmlVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2005-3634?
How severe is CVE-2005-3634?
How do I fix CVE-2005-3634?
Are you affected by CVE-2005-3634?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
