CVE Vulnerabilities

CVE-2005-3634

Published: Nov 16, 2005 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

frameset.htm in the BSP runtime in SAP Web Application Server (WAS) 6.10 through 7.00 allows remote attackers to log users out and redirect them to arbitrary web sites via a close command in the sap-sessioncmd parameter and a URL in the sap-exiturl parameter.

Affected Software

NameVendorStart VersionEnd Version
Sap_web_application_serverSap6.10 (including)6.10 (including)
Sap_web_application_serverSap6.20 (including)6.20 (including)
Sap_web_application_serverSap6.40 (including)6.40 (including)
Sap_web_application_serverSap7.0 (including)7.0 (including)

References