CVE Published: 14/02/2023 |
CVE Updated: 02/08/2024 |
CVE Year: 2023 Source: sap |
Vendor: SAP |
Product: Solution Manager Status : PUBLISHED
CVE-2023-23855 Description
SAP Solution Manager - version 720, allows an authenticated attacker to redirect users to a malicious site due to insufficient URL validation. A successful attack could lead an attacker to read or modify the information or expose the user to a phishing attack. As a result, it has a low impact to confidentiality, integrity and availability.
Metrics
CVSS Version: 3.1 |
Base Score: 6.5 MEDIUM Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L