peter bassill · operator
$ cve CVE-2005-3634 JSON

CVE-2005-3634 EXPLOIT

5.0
MEDIUM · CVSS 2.0 · EPSS 17.8% (pctl 97)

Patch early

A public exploit exists.

Description

frameset.htm in the BSP runtime in SAP Web Application Server (WAS) 6.10 through 7.00 allows remote attackers to log users out and redirect them to arbitrary web sites via a close command in the sap-sessioncmd parameter and a URL in the sap-exiturl parameter.

Scoring

CVSS5.0 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
EPSS17.76% — more likely to be exploited than 97% of all CVEs
On CISA KEVno
Public exploityes
Published2005-11-16
Last modified2026-06-16

Affected (1)

VendorProduct
sapsap web application server

Public exploits

SourceTitleDate
exploit-dbSAP Web Application Server 6.x/7.0 - Open Redirection2005-11-09

References

→ the Explorer  ·  watch your stack  ·  NVD