The J2EE Engine in SAP NetWeaver 6.40, 7.02, and previous versions allows remote malicious users to redirect users to arbitrary web sites, conduct phishing attacks, and obtain sensitive information (cookies and SAPPASSPORT) via unspecified vectors.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
sap netweaver |
||
sap netweaver 6.4 |