← back
CVE-2005-3634

CVE-2005-3634

43Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendepss 18%
from disclosure to weapon0 days
Published on NVDNov 16
1st PoCNov 9
exploitation probability
18%top 3% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
frameset.htm in the BSP runtime in SAP Web Application Server (WAS) 6.10 through 7.00 allows remote attackers to log users out and redirect them to arbitrary web sites via a close command in the sap-sessioncmd parameter and a URL in the sap-exiturl parameter.
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.