SAP Fiori Launchpad (News tile Application), versions - 750,751,752,753,754,755, allows an unauthorized attacker to send a crafted request to a vulnerable web application. It is usually used to target internal systems behind firewalls that are normally inaccessible to an attacker from the external network to retrieve sensitive / confidential resources which are otherwise restricted for internal usage only, resulting in a Server-Side Request Forgery vulnerability.
2020-11-10T17:15:13.780
2024-11-21T05:20:19.967
Modified
CVSSv3.1: 8.6 (HIGH)
AV:N/AC:L/Au:N/C:P/I:N/A:N
10.0
2.9
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | sap | fiori_launchpad_\(news_tile_application\) | 750 | Yes |
| Application | sap | fiori_launchpad_\(news_tile_application\) | 751 | Yes |
| Application | sap | fiori_launchpad_\(news_tile_application\) | 752 | Yes |
| Application | sap | fiori_launchpad_\(news_tile_application\) | 753 | Yes |
| Application | sap | fiori_launchpad_\(news_tile_application\) | 754 | Yes |
| Application | sap | fiori_launchpad_\(news_tile_application\) | 755 | Yes |