SAP NetWeaver Application Server Java(HTTP Service), versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently validate logon group in URLs, resulting in a content spoofing vulnerability when directory listing is enabled.
This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Netweaver_application_server_java | Sap | 7.10 (including) | 7.10 (including) |
Netweaver_application_server_java | Sap | 7.11 (including) | 7.11 (including) |
Netweaver_application_server_java | Sap | 7.20 (including) | 7.20 (including) |
Netweaver_application_server_java | Sap | 7.30 (including) | 7.30 (including) |
Netweaver_application_server_java | Sap | 7.31 (including) | 7.31 (including) |
Netweaver_application_server_java | Sap | 7.40 (including) | 7.40 (including) |
Netweaver_application_server_java | Sap | 7.50 (including) | 7.50 (including) |