Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-41207


SAP Biller Direct allows an unauthenticated attacker to craft a legitimate looking URL. When clicked by an unsuspecting victim, it will use an unsensitized parameter to redirect the victim to a malicious site of the attacker's choosing which can result in disclosure or modification of the victim's information.


Published

2022-11-08T22:15:17.997

Last Modified

2024-11-21T07:22:49.737

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.1 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-601

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application sap biller_direct 635 Yes
Application sap biller_direct 750 Yes

References