Vulnerabilities > CVE-2021-33707 - Unspecified vulnerability in SAP Netweaver Knowledge Management
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
LOW Integrity impact
LOW Availability impact
NONE Summary
SAP NetWeaver Knowledge Management allows remote attackers to redirect users to arbitrary websites and conduct phishing attacks via a URL stored in a component. This could enable the attacker to compromise the user's confidentiality and integrity.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 4 |
References
- http://packetstormsecurity.com/files/165748/SAP-Enterprise-Portal-Open-Redirect.html
- http://packetstormsecurity.com/files/165748/SAP-Enterprise-Portal-Open-Redirect.html
- http://seclists.org/fulldisclosure/2022/Jan/73
- http://seclists.org/fulldisclosure/2022/Jan/73
- https://launchpad.support.sap.com/#/notes/3076399
- https://launchpad.support.sap.com/#/notes/3076399
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=582222806
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=582222806