Under some circumstances the SAML SSO implementation in the SAP NetWeaver (SAP_BASIS versions 702, 730, 731, 740 and SAP ABAP Platform (SAP_BASIS versions 750, 751, 752, 753, 754), allows an attacker to include invalidated data in the HTTP response header sent to a Web user, leading to HTTP Response Splitting vulnerability.
2020-02-12T20:15:13.777
2024-11-21T05:35:15.167
Modified
CVSSv3.1: 5.8 (MEDIUM)
AV:N/AC:L/Au:N/C:N/I:P/A:N
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | sap | abap_platform | 7.50 | Yes |
Application | sap | abap_platform | 7.51 | Yes |
Application | sap | abap_platform | 7.52 | Yes |
Application | sap | abap_platform | 7.53 | Yes |
Application | sap | abap_platform | 7.54 | Yes |
Application | sap | netweaver | 7.02 | Yes |
Application | sap | netweaver | 7.30 | Yes |
Application | sap | netweaver | 7.31 | Yes |
Application | sap | netweaver | 7.40 | Yes |