Under some circumstances the SAML SSO implementation in the SAP NetWeaver (SAP_BASIS versions 702, 730, 731, 740 and SAP ABAP Platform (SAP_BASIS versions 750, 751, 752, 753, 754), allows an attacker to include invalidated data in the HTTP response header sent to a Web user, leading to HTTP Response Splitting vulnerability.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Abap_platform | Sap | 7.50 (including) | 7.50 (including) |
Abap_platform | Sap | 7.51 (including) | 7.51 (including) |
Abap_platform | Sap | 7.52 (including) | 7.52 (including) |
Abap_platform | Sap | 7.53 (including) | 7.53 (including) |
Abap_platform | Sap | 7.54 (including) | 7.54 (including) |
Netweaver | Sap | 7.02 (including) | 7.02 (including) |
Netweaver | Sap | 7.30 (including) | 7.30 (including) |
Netweaver | Sap | 7.31 (including) | 7.31 (including) |
Netweaver | Sap | 7.40 (including) | 7.40 (including) |