SAP BSP applications
cpe:2.3:a:sap:netweaver_as_abap_business_server_pages:*:*:*:*:*:*:*
A vulnerability exists in SAP BSP applications that allows an unauthenticated user to manipulate URL parameters. These parameters are not properly validated, which could lead to unvalidated redirection to attacker-controlled websites. This issue poses a low risk to the confidentiality and integrity of the application, with no impact on availability.
Exploitation of this vulnerability could result in an unvalidated open redirect, allowing users to be redirected to malicious websites.
Users are advised to consult the SAP Security Notes for guidance on addressing this vulnerability. SAP Security Notes can be accessed through the SAP for Me platform.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.