CVE-2005-3634 EXPLOIT
5.0
MEDIUM · CVSS 2.0 · EPSS 17.8% (pctl 97)
Patch early
A public exploit exists.
Description
frameset.htm in the BSP runtime in SAP Web Application Server (WAS) 6.10 through 7.00 allows remote attackers to log users out and redirect them to arbitrary web sites via a close command in the sap-sessioncmd parameter and a URL in the sap-exiturl parameter.
Scoring
| CVSS | 5.0 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
| EPSS | 17.76% — more likely to be exploited than 97% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2005-11-16 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| sap | sap web application server |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | SAP Web Application Server 6.x/7.0 - Open Redirection | 2005-11-09 |
References
- http://marc.info/?l=bugtraq&m=113156525006667&w=2
- http://secunia.com/advisories/17515/
- http://securityreason.com/securityalert/163
- http://www.cybsec.com/vuln/CYBSEC_Security_Advisory_Multiple_XSS_in_SAP_WAS.pdf
- http://www.securityfocus.com/bid/15362
- http://www.securitytracker.com/alerts/2005/Nov/1015174.html
- http://www.vupen.com/english/advisories/2005/2361
- https://exchange.xforce.ibmcloud.com/vulnerabilities/23031
- http://marc.info/?l=bugtraq&m=113156525006667&w=2
- http://secunia.com/advisories/17515/
- http://securityreason.com/securityalert/163
- http://www.cybsec.com/vuln/CYBSEC_Security_Advisory_Multiple_XSS_in_SAP_WAS.pdf
- http://www.securityfocus.com/bid/15362
- http://www.securitytracker.com/alerts/2005/Nov/1015174.html
- http://www.vupen.com/english/advisories/2005/2361
- https://exchange.xforce.ibmcloud.com/vulnerabilities/23031
→ the Explorer · watch your stack · NVD